JWT Decoder Online — Free Decode JWT Token Header & Payload

Decode a JSON Web Token in your browser to inspect its header and payload. Signature is NOT validated — debugging only.

Paste a JWT below. Header and payload are decoded from Base64URL locally; the token never leaves the page.

Common use cases

Frequently asked questions

Why isn't the signature verified?+

Verification needs the issuer's public key (RS256 / ES256) or shared secret (HS256). That is an infrastructure decision — use jose / jsonwebtoken with the right key for that. This tool decodes only.

Is my token safe to paste here?+

Decoding runs entirely in your browser; the token never leaves the page. However, an ACTIVE access token still carries your identity — if it is in use, redact sensitive claims after debugging.

Why does my token decode to gibberish?+

It is probably not a JWT. Real JWTs always have three Base64URL parts separated by dots (header.payload.signature). Opaque tokens (random strings) do not decode to JSON.

Tools

SECURITY TIP

Using default passwords? Protect your network with NordVPN encryption.