JWT Decode

Decode a JWT's header and payload to readable JSON without verifying the signature. See the algorithm and claims instantly. Nothing leaves your browser.

Loading tool…

Worked examples

  • A well-formed JWT

    The everyday case: reading the claims and algorithm out of a token copied from a login response or an Authorization header, without needing the signing key.

  • Text that isn't a JWT at all

    A JWT always has exactly three dot-separated parts (header, payload, signature) — anything else is rejected immediately with a clear reason.

  • Malformed payload segment

    The header can decode successfully while the payload fails — the tool reports exactly which segment broke and still shows what it could decode.

What this tool does

A JSON Web Token (JWT) is a compact, three-part string used to carry claims — such as a user ID, an expiration time, or permission scopes — between a client and a server. This tool decodes a JWT's header and payload back to readable JSON entirely in your browser. It does not verify the signature; it only reads the two segments that are plain Base64url-encoded JSON, not the cryptographically signed part.

When you need it

  • Inspecting what's actually inside an access token or ID token your application received, while debugging an authentication flow.
  • Checking which algorithm (alg) and claims a third-party API's token uses before writing code to consume it.
  • Confirming a token you generated in a test environment contains the claims you expected, without needing the signing key on hand.
  • Understanding an expired-token or invalid-claim error by seeing exactly what the token says, independent of whether it's cryptographically valid.

How a JWT is structured

A JWT is three Base64url-encoded segments joined by dots: header.payload.signature. The header typically names the signing algorithm (alg) and token type (typ); the payload carries the actual claims — arbitrary key-value data about the subject, issuer, expiration, and anything else the issuer chose to include. The signature is a cryptographic value computed over the header and payload using a secret or private key, and it's the only part that proves the token is authentic and unmodified.

This tool decodes the first two segments — plain JSON, readable by anyone without any key — and reports the algorithm and token type it finds in the header. It leaves the signature alone entirely, since checking it correctly requires the issuer's secret or public key, which a generic browser tool has no way to obtain or verify against.

Why unverified claims can't be trusted

Because the header and payload are just Base64url-encoded JSON, not encrypted, anyone can construct a JWT with any claims they like — a forged token decodes just as cleanly as a legitimate one. The signature is what separates a real, unmodified token from a forgery, and this tool doesn't check it. Use it to read and debug a token's contents, never to authenticate or authorize a request; that decision belongs to server-side code using a proper JWT library that verifies the signature against the correct key and algorithm.

What the tool reports on invalid input

A leading Bearer prefix, as copied from an Authorization header, is ignored. A token that doesn't have exactly three dot-separated parts is rejected immediately, since that structure is required by the JWT format itself. If a segment isn't valid Base64url or doesn't decode to valid JSON, the tool reports exactly which segment failed and why — and still shows whichever segment did decode successfully, rather than discarding everything on a partial failure.

Limits

Input is capped at 2 MB of text, far more than any real JWT needs. This tool never contacts a server, which matters since a real token can carry sensitive session data — but always be cautious pasting a production token into any browser tool, including this one, and prefer test tokens where possible.

Frequently asked questions

Is my token uploaded anywhere?
No. Decoding runs entirely in your browser; nothing is sent to a server — important for a token that may carry real session claims.
Does this verify the signature?
No. This tool only decodes the header and payload, which are just Base64url-encoded JSON — it does not check the signature against a secret or public key, so it cannot tell you whether a token is authentic.
Why shouldn't I trust an unverified token's claims?
Anyone can construct a JWT with any header and payload they like; only signature verification (with the correct key) proves the claims came from the expected issuer and weren't tampered with.
What does the 'alg' field in the header mean?
It names the signing algorithm the token claims to use, such as HS256 or RS256 — the receiving system must use that same algorithm and the correct key to verify the token, and never trust the 'alg' value the token itself declares when verifying.