QuicklySorted

JWT Decoder

Decode a JSON Web Token for inspection. Decoding does not verify its signature or authenticity.

0 characters · 100,000 remaining

0 characters

0 characters

JWT content stays in this browser. No signature verification is performed.

On this device

No signup. Your input is never uploaded.

How to use the JWT Decoder

  1. Paste the whole token, with its three dot-separated parts, into the JWT input.

  2. Read the decoded header, which says how the token was signed.

  3. Read the decoded payload, which holds the claims such as who the token is for and when it expires.

Questions about the JWT Decoder

A JSON Web Token is a signed string used to prove who someone is. It has three parts separated by dots: a header, a payload with the claims, and a signature.

No. This tool only decodes and shows the header and payload. It does not check the signature, so a decoded token is not proof that the token is genuine. Verify tokens in your own server code.

Decoding happens in your browser, so the token is not sent anywhere. Even so, treat live tokens like passwords and avoid pasting ones that grant real access.

Missing a tool?

Tell us what you wanted to do. Your ideas decide which tools we build next.

Suggest a tool