All tools

JWT Decoder

Inspect a token's header and payload (signature not verified).

Everything here runs entirely in your browser. Nothing you type, paste, or upload is ever sent to a server, logged, or stored.

About the JWT Decoder

Splits a JSON Web Token into its three parts and decodes the header and payload so you can read the claims — who issued it, who it is for, when it expires, and whatever else it carries.

When you would use it

  • Checking why a token is being rejected as expired.
  • Seeing which claims and scopes a token actually carries.
  • Confirming which algorithm and key id a token declares.

What it does not tell you

THE SIGNATURE IS NOT VERIFIED, and this is the thing to understand about JWTs generally. A token is signed, not encrypted: anyone holding it can read every claim inside, and the decoded content here proves only what the token says about itself. Deciding whether to trust it requires checking the signature against the issuer key, which needs that key and is not something a browser page can do for you. Treat any token you paste as a live credential.