JWT Decoder
Decode a JWT into its header, payload, and signature.
Decode JSON Web Tokens and inspect header, payload, and signature. Free, offline, runs in your browser. Read more Show less
What is a JWT?
A JSON Web Token is a compact, URL-safe way to represent claims between two parties. It is three Base64URL-encoded parts separated by dots: the header (algorithm and type), the payload (claims), and the signature.
JWTs are commonly used as bearer tokens for API authentication. The signature proves the token was issued by someone holding the signing key. Decoding a JWT does not verify it: you must check the signature separately.
How to use
Paste a JWT into the input. The header and payload are decoded and shown as JSON. The signature is shown as-is and is not verified.
FAQ
Is my token sent anywhere?
No. Decoding happens entirely in your browser.
Does this verify the signature?
No. Verification requires the signing secret or public key and is a separate operation. This tool is for inspecting the contents. A signature verification tool is on the roadmap.
What are the standard claims?
Common claims: iss (issuer), sub (subject), aud (audience), exp (expiry, Unix seconds), nbf (not before), iat (issued at), jti (JWT ID).
Why does my token start with "eyJ"?
That is the Base64URL encoding of {", the start of every JWT header.
Signatures are shown but not verified. Use a signature verification tool for that.