JWT Decoder
Inspect JSON Web Tokens (JWT) instantly. Everything runs offline in your browser — your tokens never leave your device.
Privacy First: This tool uses pure client-side JavaScript. No data is transmitted to any server, making it safe for production tokens.
This jwt decoder allows you to inspect the contents of a JSON Web Token without sending your sensitive data to a remote server. It parses the three parts of a JWT—the header, the payload, and the signature—to reveal the claims and metadata stored inside.
Developers typically use this tool during debugging to verify that a token contains the correct user ID, expiration date, or permission scopes. Because the tool runs entirely in your browser, your tokens are never uploaded or logged, making it safe for use with development and staging environments.
Note that this tool only decodes the token; it does not verify the signature. To verify if a token is authentic and untampered with, you must use your secret key or public certificate within your application backend.
How to Use JWT Decoder
- Paste your token — Copy your encoded JWT and paste it into the input field.
- Review the header — Check the decoded header to see the algorithm and token type.
- Inspect the payload — Examine the claims, such as sub, exp, and iat, in the payload section.
Frequently Asked Questions
Is my token sent to a server?
No. This tool uses client-side JavaScript to decode the Base64Url encoded strings. All processing happens locally in your browser, meaning your token data never leaves your machine.
Can this tool verify if a JWT is valid?
No. Decoding is different from verification. This tool reveals the data inside the token, but it cannot tell you if the signature is valid because it does not have your private secret key.
What is the difference between decoding and decrypting?
JWTs are typically signed and encoded, not encrypted. Decoding simply converts the Base64Url format back into readable JSON. Decrypting would require a key to unlock an encrypted JWE token.
Why is my token showing as invalid?
Ensure you have pasted the entire token, including the two dots that separate the header, payload, and signature. If the string is malformed or truncated, the decoder cannot parse the JSON.