Small ToolsAll tools
← All tools / Security
Security utility

JWT Decoder

Decode a JWT header and payload without verifying its signature.

● This tool runs entirely in your browser. Your input is never uploaded to our servers.

Decoding does not verify the signature. Treat all claims as untrusted.

Output
Your result will appear here…

How to use JWT Decoder

  1. Paste a JWT with three dot-separated segments.
  2. Select Decode to inspect its header and payload.
  3. Never treat decoded claims as verified until the signature is validated.

Example

Input:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTEyMyIsImV4cCI6MTczNTY4OTYwMH0.signature

Output:

Header: {
  "alg": "HS256",
  "typ": "JWT"
}
Payload: {
  "sub": "user-123",
  "exp": 1735689600
}

Use cases

About this tool

Decode a JWT header and payload without verifying its signature. Processing happens locally in your browser, so your input is not sent to a server or included in analytics.

Frequently asked questions

Does decoding verify the JWT signature?

No. Decoding only Base64URL-decodes the header and payload. It does not authenticate the token or validate claims.

Is the token sent to a server?

No. Decoding happens in your browser.

Should I paste a production access token?

Avoid exposing live credentials. Use a revoked or synthetic token for inspection.

Related tools