JWT decoder. Decode and inspect JSON Web Token headers, payloads, and signatures instantly in your browser.
100% browser-based — your data never leaves your device
Decode and inspect JWT tokens instantly.
Copy the full JWT (including all 3 dot-separated parts) and paste it into the input field.
Press the Decode Token button to parse the header, payload, and signature.
Review the decoded header (algorithm, type) and payload (claims like sub, exp, iat) in formatted JSON.
Ctrl+Enter to decode
Decode and inspect JWT tokens instantly.
Password GeneratorGenerate strong, secure random passwords with customizable options.
Passphrase GeneratorGenerate memorable, secure passphrases from word lists.
UUID GeneratorGenerate UUID v4 identifiers instantly.
UUID ValidatorValidate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash GeneratorGenerate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.
JWT GeneratorGenerate signed JWT tokens for testing with custom headers and payloads.
Bcrypt Hash GeneratorGenerate bcrypt password hashes with configurable salt rounds.
API Key GeneratorGenerate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.
HMAC GeneratorGenerate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.
AES EncryptEncrypt and decrypt text using AES-256-GCM with a password-based key.
Follow these steps to inspect and debug JSON Web Tokens without exposing your secrets:
All decoding happens locally using base64 decoding. Your tokens are never sent to any server.
JWT tokens often contain user identity data, session information, API permissions, and authentication credentials. Sending these tokens to external decoding services exposes your entire authentication state to third parties.
This JWT Decoder performs base64url decoding entirely in your browser. Your tokens, secrets, and authentication data never leave your device, making it safe for debugging production tokens and testing authentication flows.
Copy the full JWT (including all 3 dot-separated parts) and paste it into the input field.
Press the Decode Token button to parse the header, payload, and signature.
Review the decoded header (algorithm, type) and payload (claims like sub, exp, iat) in formatted JSON.
Practical examples to help you get the most out of JWT Decoder:
// Paste this JWT into the decoder: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
JWT payloads are only base64-encoded, not encrypted. Anyone with the token can read the contents. Use JWE (JSON Web Encryption) if you need confidentiality.
Always verify the JWT signature on the server side. Without verification, an attacker can forge tokens with arbitrary claims.
Yes. This tool only decodes — it does not verify signatures or send tokens to any server.
No. Signature verification requires the secret or public key used to sign the token.
Claims such as user ID (sub), expiration time (exp), issued at (iat), issuer (iss), and custom data.
View the token type and signing algorithm from the JWT header.
Decode and format the payload with user data, expiration (exp), issued-at (iat), and custom claims.
View the JWT signature portion. Note: decoding only, not signature verification.
Your JWT token is decoded entirely in your browser.
JWT Decoder is useful in a variety of scenarios across different workflows:
Inspecting JWT tokens during API authentication debugging
Verifying JWT claim values and expiration times
Analyzing JWT structure for security auditing
JWT payloads are base64-encoded, not encrypted. Anyone with the token can read the claims. Never store sensitive data in a JWT payload.
Always verify the alg header matches expectations. Some attacks exploit algorithm confusion by changing alg to 'none'.
Explore more tools in the Developer Workspace workspace:
JSON Formatter
Format, minify, validate, and explore JSON with tree view, JSONPath queries, and multi-format export — the complete JSON workbench.
JSON Validator
Validate JSON data and detect syntax errors with detailed error messages and line numbers.
JSON Compare
Compare two JSON files side by side with real-time diff highlighting.
JSON Path Tester
Test JSONPath expressions against JSON data and see matched results.
JSON Query Tool
Extract values from JSON using dot-notation and bracket-notation paths.
JSON Schema Generator
Generate JSON Schema (draft-07) from sample JSON data automatically.