JWT Decode
Decode a JWT's header and payload to readable JSON without verifying the signature. See the algorithm and claims instantly. Nothing leaves your browser.
Worked examples
- A well-formed JWT
The everyday case: reading the claims and algorithm out of a token copied from a login response or an Authorization header, without needing the signing key.
- Text that isn't a JWT at all
A JWT always has exactly three dot-separated parts (header, payload, signature) — anything else is rejected immediately with a clear reason.
- Malformed payload segment
The header can decode successfully while the payload fails — the tool reports exactly which segment broke and still shows what it could decode.
What this tool does
A JSON Web Token (JWT) is a compact, three-part string used to carry claims — such as a user ID, an expiration time, or permission scopes — between a client and a server. This tool decodes a JWT's header and payload back to readable JSON entirely in your browser. It does not verify the signature; it only reads the two segments that are plain Base64url-encoded JSON, not the cryptographically signed part.
When you need it
- Inspecting what's actually inside an access token or ID token your application received, while debugging an authentication flow.
- Checking which algorithm (
alg) and claims a third-party API's token uses before writing code to consume it. - Confirming a token you generated in a test environment contains the claims you expected, without needing the signing key on hand.
- Understanding an expired-token or invalid-claim error by seeing exactly what the token says, independent of whether it's cryptographically valid.
How a JWT is structured
A JWT is three Base64url-encoded segments joined by dots: header.payload.signature. The header typically names the signing algorithm (alg) and token type (typ); the payload carries the actual claims — arbitrary key-value data about the subject, issuer, expiration, and anything else the issuer chose to include. The signature is a cryptographic value computed over the header and payload using a secret or private key, and it's the only part that proves the token is authentic and unmodified.
This tool decodes the first two segments — plain JSON, readable by anyone without any key — and reports the algorithm and token type it finds in the header. It leaves the signature alone entirely, since checking it correctly requires the issuer's secret or public key, which a generic browser tool has no way to obtain or verify against.
Why unverified claims can't be trusted
Because the header and payload are just Base64url-encoded JSON, not encrypted, anyone can construct a JWT with any claims they like — a forged token decodes just as cleanly as a legitimate one. The signature is what separates a real, unmodified token from a forgery, and this tool doesn't check it. Use it to read and debug a token's contents, never to authenticate or authorize a request; that decision belongs to server-side code using a proper JWT library that verifies the signature against the correct key and algorithm.
What the tool reports on invalid input
A leading Bearer prefix, as copied from an Authorization header, is ignored. A token that doesn't have exactly three dot-separated parts is rejected immediately, since that structure is required by the JWT format itself. If a segment isn't valid Base64url or doesn't decode to valid JSON, the tool reports exactly which segment failed and why — and still shows whichever segment did decode successfully, rather than discarding everything on a partial failure.
Limits
Input is capped at 2 MB of text, far more than any real JWT needs. This tool never contacts a server, which matters since a real token can carry sensitive session data — but always be cautious pasting a production token into any browser tool, including this one, and prefer test tokens where possible.
Frequently asked questions
- Is my token uploaded anywhere?
- No. Decoding runs entirely in your browser; nothing is sent to a server — important for a token that may carry real session claims.
- Does this verify the signature?
- No. This tool only decodes the header and payload, which are just Base64url-encoded JSON — it does not check the signature against a secret or public key, so it cannot tell you whether a token is authentic.
- Why shouldn't I trust an unverified token's claims?
- Anyone can construct a JWT with any header and payload they like; only signature verification (with the correct key) proves the claims came from the expected issuer and weren't tampered with.
- What does the 'alg' field in the header mean?
- It names the signing algorithm the token claims to use, such as HS256 or RS256 — the receiving system must use that same algorithm and the correct key to verify the token, and never trust the 'alg' value the token itself declares when verifying.