Encoding · Developer

JWT decoder.

Paste a JSON Web Token to see its decoded header and payload instantly. Everything runs in your browser — the token never leaves your machine. This decodes structure only; it does not verify the signature.

Advertisement

Input

Header.Payload.Signature, dot-separated. Try the button below for a generated example.

Decoded

Paste a JWT and press Decode.

What a JWT is

A JSON Web Token (RFC 7519) is three Base64URL-encoded segments joined by dots: a header (algorithm and token type), a payload (the claims — whatever data the issuing application put there), and a signature (a MAC or digital signature over the first two segments, used to verify the token wasn't tampered with). Decoding the header and payload requires no secret key; verifying the signature does, which is why this tool only decodes — it never claims a token is valid or unmodified.

Three registered claims are shown as human-readable dates when present: exp (expiration time), iat (issued at), and nbf (not before) — each a Unix timestamp in seconds per RFC 7519 section 4.1.

Spec: RFC 7519 — JSON Web Token (JWT) and RFC 7515 — JSON Web Signature (compact serialization).

Frequently asked questions

Does this verify the signature?

No. Verifying a signature requires the secret key (HMAC algorithms) or the signer's public key (RSA/ECDSA algorithms), which this tool never asks for. It only decodes the header and payload structure.

Is my token sent to a server?

No. All decoding happens in your browser with standard Base64URL and JSON parsing — nothing is uploaded or logged.

Why can't I read the signature as text?

The signature isn't text-encoded data — it's raw MAC or signature bytes. Decoding it as UTF-8 would just produce garbage; this tool shows it as its original Base64URL string instead.

Structure only — not a security check

This tool decodes a JWT's header and payload for inspection. It does not verify the signature, does not check expiration against the current time, and a successfully decoded token is not proof that it is genuine, current, or untampered with. Never treat an unverified JWT as trusted input in your own application.

Advertisement
Advertisement
Listening…