Tooleux

JWT Decoder

JWT (3)

Decode a JWT into its header, payload, and signature.

Runs in your browser. Nothing leaves your device.
Decode JSON Web Tokens and inspect header, payload, and signature. Free, offline, runs in your browser. Read more Show less

What is a JWT?

A JSON Web Token is a compact, URL-safe way to represent claims between two parties. It is three Base64URL-encoded parts separated by dots: the header (algorithm and type), the payload (claims), and the signature.

JWTs are commonly used as bearer tokens for API authentication. The signature proves the token was issued by someone holding the signing key. Decoding a JWT does not verify it: you must check the signature separately.

How to use

Paste a JWT into the input. The header and payload are decoded and shown as JSON. The signature is shown as-is and is not verified.

FAQ

Is my token sent anywhere?

No. Decoding happens entirely in your browser.

Does this verify the signature?

No. Verification requires the signing secret or public key and is a separate operation. This tool is for inspecting the contents. A signature verification tool is on the roadmap.

What are the standard claims?

Common claims: iss (issuer), sub (subject), aud (audience), exp (expiry, Unix seconds), nbf (not before), iat (issued at), jti (JWT ID).

Why does my token start with "eyJ"?

That is the Base64URL encoding of {", the start of every JWT header.

Loads a test value into the form
JWT
Header
 
Payload
 
Signature
 

Signatures are shown but not verified. Use a signature verification tool for that.