Developer
JWT Decoder
Inspect JWTs safely without pasting secrets into a third-party site. Processing stays on your device — no upload, no account.
How to use JWT Decoder
- Paste a JWT (header.payload.signature).
- Inspect decoded header and payload JSON.
- Copy parts as needed - signature is not verified.
Why use this free jwt decoder tool?
- All processing happens locally in your browser. Your files are never uploaded to a server.
- Base64URL decode.
- Pretty-printed JSON.
- Clear unverified warning.
Technical details
JWT (JSON Web Token) is a compact, URL-safe token format used for authentication and authorization in web applications and APIs. A JWT has three Base64URL-encoded segments separated by dots: header.payload.signature. The header describes the signing algorithm (e.g., HS256 for HMAC-SHA256 or RS256 for RSA). The payload contains claims - JSON key-value pairs like {"sub":"user123","exp":1700000000,"role":"admin"}. The signature is computed from the header and payload using a secret key (for HMAC) or a private key (for RSA), and it proves the token has not been tampered with.
This tool decodes the header and payload by splitting the JWT on dots, Base64URL-decoding the first two segments, and parsing them as JSON. The decoded JSON is pretty-printed so you can inspect claims like user ID (sub), expiration (exp), issuer (iss), and custom claims. All decoding happens in your browser - the JWT is never uploaded to a server. This is important for security: JWTs often contain sensitive information and can grant access to APIs or user accounts if leaked. Never paste production JWTs into untrusted online tools that may log or store tokens.
This tool does NOT verify the JWT signature. Signature verification requires the secret key (for HMAC) or public key (for RSA), which the browser does not have. Without signature verification, a decoded JWT cannot be trusted for authentication or authorization. An attacker could create a fake JWT with claims like {"sub":"admin","exp":9999999999} and this tool would decode it successfully, even though it is not signed by the real server. Always verify JWTs on the server side before trusting the claims. Use this tool only for debugging and inspecting JWTs during development.
The tool also does NOT validate the exp (expiration) or nbf (not before) claims. An expired JWT will decode successfully and show the expired timestamp. You must check the exp claim yourself and compare it to the current Unix timestamp. JWE (JSON Web Encryption) tokens, which have five Base64URL segments instead of three, are not supported. This tool only handles JWS (JSON Web Signature) tokens with the compact serialization format (three segments).
Worked example: A developer is integrating with a third-party API that returns a JWT access token. The API documentation says the token contains a "userId" claim, but the developer is not sure if the token is structured correctly. The developer pastes the JWT into this tool and sees the decoded payload: {"sub":"abc123","userId":"user_456","exp":1700000000,"iss":"api.example.com"}. The userId claim is present, so the developer can proceed with the integration. Because the decoding was done locally in the browser, the JWT (which grants access to the developer's test account) never left the developer's laptop.
JWT Decoder FAQ
Is my JWT uploaded to a server when I decode it?
No. The entire decoding process happens in your browser using JavaScript's atob() function (Base64 decoding) and JSON.parse(). Your JWT never leaves your device. This is critical for security: JWTs are secrets that grant access to APIs and user accounts. Never paste production JWTs into untrusted online tools. You can disconnect from the internet after the page loads and the decoder will still work.
Does this tool verify the JWT signature?
No. Signature verification requires the secret key (for HMAC algorithms like HS256) or the public key (for RSA algorithms like RS256). This tool does not have access to those keys and cannot verify signatures. It only decodes the Base64URL segments and parses the JSON. Never use this tool to authenticate users or authorize API requests - always verify JWTs on the server side with the proper key.
Can I decode JWE (JSON Web Encryption) tokens?
No. This tool only supports JWS (JSON Web Signature) tokens with the compact serialization format: three Base64URL segments separated by dots (header.payload.signature). JWE tokens have five segments and use encryption instead of signing. If you paste a JWE token, the tool will show an error because it cannot parse the structure.
Is it safe to paste production JWTs into this tool?
The tool processes JWTs locally in your browser, so they are not uploaded to a server. However, the JWT remains in your browser tab's memory and browser history until you close the tab or clear it. For maximum security, avoid pasting production JWTs with real user data or account access. Use test tokens or redacted tokens (change the signature to xxx) for debugging. If you must decode a production JWT, close the tab afterward.
Why does the tool say the token is "unverified" even though it decodes successfully?
Decoding and verifying are different operations. Decoding parses the Base64URL segments and shows you the JSON header and payload. Verifying checks the signature to ensure the token was issued by the real server and has not been tampered with. This tool only decodes - it cannot verify without the secret key. An attacker could create a fake JWT with forged claims and this tool would decode it successfully, so never trust decoded JWTs for authentication.
Related free converters
More private browser tools people use with jwt decoder.