JWT decoder online — gratis token header & payload decoderen

Decodeer een JSON Web Token in je browser om header en payload te inspecteren. Handtekening wordt NIET gevalideerd — alleen debugging.

Plak een JWT hieronder. Header en payload worden lokaal van Base64URL gedecodeerd; het token verlaat de pagina niet.

Gangbare toepassingen

Veelgestelde vragen

Why isn't the signature verified?+

Verification needs the issuer's public key (RS256 / ES256) or shared secret (HS256). That is an infrastructure decision — use jose / jsonwebtoken with the right key for that. This tool decodes only.

Is my token safe to paste here?+

Decoding runs entirely in your browser; the token never leaves the page. However, an ACTIVE access token still carries your identity — if it is in use, redact sensitive claims after debugging.

Why does my token decode to gibberish?+

It is probably not a JWT. Real JWTs always have three Base64URL parts separated by dots (header.payload.signature). Opaque tokens (random strings) do not decode to JSON.

Tools

BEVEILIGINGSTIP

Gebruikt u standaardwachtwoorden? Bescherm uw netwerk met NordVPN-versleuteling.