jwt

JWT Decoder

Decode the header and payload of a JWT without verification. Runs locally — tokens never leave your browser.

Paste a JWT to decode its header and payload as JSON. No signature verification, and the token never leaves your browser.

JWT token
Header
Payload

What this JWT decoder does

Decode the header and payload of a JSON Web Token (JWT) locally and read them as formatted JSON. The token is never transmitted. Decoding is decode-only — the signature is never verified as part of decoding. Optional local signature verification is available only for HMAC tokens (HS256/HS384/HS512) and only when you supply the secret. Asymmetric algorithms (RS/PS/ES) are never verified here, because doing so would require the issuer's public key.

Anatomy of a JWT

Three parts. A JWT has the form header.payload.signature, each part Base64URL-encoded. This tool decodes the first two.
Header describes the signing algorithm, commonly alg: HS256 or RS256.
Payload holds claims such as sub, exp (expiry), iat (issued at), andaud (audience). Expiry is a Unix timestamp in seconds.
Signature is not decoded here. Never trust the payload of a JWT without verifying the signature on the server that issued it.

Frequently asked questions

How do I decode a JWT?

Paste the token into the input pane and its header and payload are decoded automatically and shown as readable JSON.

Does it verify the signature?

No. The decoder is deliberately read-only — it shows the header and payload without verifying the signature. Use the JWT Generator with a known secret to validate tokens.

Is my token uploaded?

No. Decoding runs entirely in your browser, so tokens never leave the page.

Does JWT Decoder upload my data?

No. JWT Decoder runs entirely in your browser — your input never leaves this page.

Is JWT Decoder free to use?

Yes. JWT Decoder is completely free, with no account and nothing to sign up for.

Updated 2026-08-07 · Runs in your browser — your data never leaves this page.