Paste a JSON Web Token to read its header and payload. This tool only decodes — it never verifies the signature and never uploads the token. 100% Local
How to Use the JWT Decoder
Paste a token in the form header.payload.signature and the header and payload JSON are decoded right away. Long payloads are shown as pretty-printed JSON.
What it does and does not do
It base64url-decodes the header and payload segments.
It reports the declared algorithm and whether an expiry claim exists.
It does not verify the signature — a decoded token proves nothing about authenticity.
Features
Header and payload decoded as readable JSON
Shows the declared algorithm and expiry presence
No signature verification, by design and clearly stated
All processing runs locally in your browser. Your token is not uploaded to any server.
Decoding is not verification — never trust a token just because it decodes.