JWT Decoder
Paste a JWT to instantly see its decoded header and payload as readable JSON.
Your files never leave your device — everything runs in your browser.
This only decodes the token — it doesn't verify the signature, and nothing is sent to a server. Never paste a token you don't trust into an untrusted site, since a JWT's payload is readable by anyone who has it.
How to Use
- 1Paste your JWT (JSON Web Token) into the text box.
- 2The decoded header and payload appear automatically.
- 3Copy either section, or check the signature and expiry.
Frequently Asked Questions
Is my token sent to a server?
No — decoding happens entirely in your browser using standard base64url decoding. Your token never leaves your device.
Does this verify the token's signature?
No. This tool only decodes the header and payload for inspection; it doesn't check whether the signature is valid, which requires the issuer's secret or public key.