JWT Decoder
Decode the header and payload of a JWT without verification. Runs locally — tokens never leave your browser.
Paste a JWT to decode its header and payload as JSON. No signature verification, and the token never leaves your browser.
What this JWT decoder does
Decode the header and payload of a JSON Web Token (JWT) locally and read them as formatted JSON. The token is never transmitted. Decoding is decode-only — the signature is never verified as part of decoding. Optional local signature verification is available only for HMAC tokens (HS256/HS384/HS512) and only when you supply the secret. Asymmetric algorithms (RS/PS/ES) are never verified here, because doing so would require the issuer's public key.
Anatomy of a JWT
header.payload.signature, each part Base64URL-encoded. This tool decodes the first two.alg: HS256 or RS256.sub, exp (expiry), iat (issued at), andaud (audience). Expiry is a Unix timestamp in seconds.Frequently asked questions
How do I decode a JWT?
Paste the token into the input pane and its header and payload are decoded automatically and shown as readable JSON.
Does it verify the signature?
No. The decoder is deliberately read-only — it shows the header and payload without verifying the signature. Use the JWT Generator with a known secret to validate tokens.
Is my token uploaded?
No. Decoding runs entirely in your browser, so tokens never leave the page.
Does JWT Decoder upload my data?
No. JWT Decoder runs entirely in your browser — your input never leaves this page.
Is JWT Decoder free to use?
Yes. JWT Decoder is completely free, with no account and nothing to sign up for.