TOOLDENDEVELOPERON-DEVICE
JWT Decoder
Paste a JWT and inspect its header and payload as formatted JSON. Tokens are decoded in your browser, nothing is uploaded, and the signature is never verified.
HOW TO USE
- 1Paste a JWT, header.payload.signature.
- 2The header and payload are decoded as you type, with a copy button each.
- 3The raw signature is displayed separately.
- 4The signature is never verified; this tool only decodes.
EXAMPLE
INPUT
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMifQ.abc123...
OUTPUT
Header: {"alg":"HS256","typ":"JWT"} · Payload: {"sub":"123"}FAQ
Does this tool verify the signature?
No. It only decodes — the signature is never verified, and the token is never sent anywhere.
Why does it show the signature separately?
The signature is the base64url-encoded part after the second dot; it is displayed so you can see all three segments clearly.
What information is in a JWT?
Three parts: header (algorithm and type), payload (claims like user ID and expiry), and signature (verification data).
Can it verify JWT signatures?
No. Decoding reads the payload without validation. Use your backend to verify signatures against the secret key.