Skip to content
DevTrove

Security & Crypto

JWT Decoder

Decode and inspect a JWT's header and payload locally. Decoding does not verify the signature.

Runs in your browser

Decoding is not verification.

This tool only reads the token; it does not check the signature or whether the token is valid. JWTs often contain sensitive data and can work like passwords — avoid pasting production tokens. Decoding runs in your browser and the tool does not intentionally send your token to a server.

How to use

  1. Paste a JWT (header.payload.signature) into the input box — without a "Bearer " prefix.
  2. Select Decode, or press Ctrl+Enter (⌘+Enter on Mac) in the input box.
  3. Read the header, payload and registered claims. Remember that none of it has been verified.

Decoding is not verification

A JWT's header and payload are only Base64URL-encoded JSON, so anyone can read them — and anyone can create a token with any content. This tool decodes the token so you can inspect it. It does not check the signature.

A valid-looking JWT payload is not proof that the token is valid. Decoding does not prove that the token is authentic, that its issuer is trusted, that it has not been modified, that the signature is correct, or that the user it describes is authenticated or authorized. Only the receiving application can verify the signature with the right key.

The three parts of a JWT

Header: JSON describing the token, such as its type (typ) and the signing algorithm it claims to use (alg). The alg value is shown as data only; a token whose alg is "none" declares itself unsigned, and this tool does not judge that either way.

Payload: JSON containing the claims, such as the issuer (iss), subject (sub), audience (aud), expiration time (exp), not-before time (nbf), issued-at time (iat) and token ID (jti). Time claims are shown as dates, and exp and nbf are compared with your device clock — purely an interpretation of the numbers in the token.

Signature: the third part. Its length is shown, but it is not checked, so its presence proves nothing.

Strict decoding

The token is decoded exactly as entered. It must have exactly three dot-separated parts, use unpadded Base64URL, and contain no spaces or line breaks; the header and payload must be UTF-8 JSON objects. Malformed tokens are reported, never repaired. Encrypted tokens (JWE, five parts) cannot be decoded.

The header and payload are shown with indentation added, but every value is displayed exactly as encoded, including large numbers and duplicate keys. Input is limited to 5,000,000 characters.

FAQ

Is my token sent anywhere?
Decoding runs in your browser, and the tool does not intentionally send your token to a server. It is not stored or added to the page URL. Even so, treat real tokens as secrets: anyone who has a valid token may be able to use it.
Does this tool tell me whether a token is valid?
No. It does not verify signatures, check issuers or audiences, or validate tokens in any way. Expiry information is only a reading of the exp and nbf numbers in the token.
Why is my token rejected?
Common causes are a "Bearer " prefix or a trailing line break, a token cut off while copying (not three parts), or an encrypted JWE token. The error message names the part and position of the problem without repeating the token.