JWT Decoder
Paste a JWT (JSON Web Token) and see the header and payload readably — entirely in your own browser.
How to use the JWT decoder
- Paste your JWT token (three parts separated by periods).
- The header and payload are decoded and formatted automatically as readable JSON.
- The signature is shown raw, since verifying it requires the secret/key the token was signed with.
What is a JWT?
A JWT (JSON Web Token) is a compact, URL-safe format for transferring information between two parties, widely used for authentication and authorization in web APIs. A token consists of three Base64URL-encoded parts separated by periods: header (algorithm and token type), payload (the actual data/"claims"), and signature (used to verify the token hasn't been altered).
The header and payload are only encoded, not encrypted — anyone can read the contents without any secret, exactly like this tool does. The signature, on the other hand, requires the secret (or private key) the token was signed with to be verified, which doesn't happen here.
Frequently asked questions
Does this tool verify that the token is genuine?
No. The tool only decodes the header and payload, which are readable without any secret. Verifying the signature requires the secret or public key the token was signed with, and is normally done server-side.
Is it safe to paste a real JWT token here?
Decoding happens entirely locally in your own browser and is never sent to any server, but still be cautious about sharing real production tokens — treat them as sensitive information.
Why am I getting an error?
The token is likely missing one or more of its three period-separated parts, or the header/payload section isn't valid Base64URL-encoded JSON.