JWT Decoder
Decode JWT headers and payloads locally without sending tokens to a server.
// Waiting for JWT string...
// Waiting for JWT string...
About this tool
The JWT Decoder splits a JSON Web Token into its header, payload, and signature, then pretty-prints the claims — expiry, issuer, subject, and custom fields. Paste any token to inspect what it carries without sending it anywhere.
Note that decoding is not verification: this tool shows you the token's contents, but only the issuing server can validate the signature. Never paste production secrets into any online tool you don't trust — this one runs fully offline in your browser.
How to use
- 1Paste a JWT — three Base64 segments separated by dots.
- 2The header and payload claims decode instantly in the panels below.
- 3Everything stays in your browser; tokens are never sent anywhere.
Frequently asked questions
Yes — decoding happens entirely in your browser and the token is never transmitted. Still, treat decoded tokens carefully: they may contain session credentials, so don't share screenshots of them.