Decoder JWT online — decodifica gratis header e payload

Decodifica un JSON Web Token nel browser per ispezionare header e payload. La firma NON viene validata — solo debug.

Incolla un JWT sotto. Header e payload sono decodificati localmente da Base64URL; il token non lascia la pagina.

Casi d'uso comuni

Domande frequenti

Why isn't the signature verified?+

Verification needs the issuer's public key (RS256 / ES256) or shared secret (HS256). That is an infrastructure decision — use jose / jsonwebtoken with the right key for that. This tool decodes only.

Is my token safe to paste here?+

Decoding runs entirely in your browser; the token never leaves the page. However, an ACTIVE access token still carries your identity — if it is in use, redact sensitive claims after debugging.

Why does my token decode to gibberish?+

It is probably not a JWT. Real JWTs always have three Base64URL parts separated by dots (header.payload.signature). Opaque tokens (random strings) do not decode to JSON.

Strumenti

CONSIGLIO DI SICUREZZA

Usi password predefinite? Proteggi la tua rete con la crittografia NordVPN.