This tool only decodes the JWT. It does not verify the signature. Never paste sensitive production tokens into online tools.
How do you decode a JWT?
A JWT has three dot-separated parts - header, payload, and signature - and the first two are Base64URL-encoded, not encrypted. Decoding reveals the claims in plain text. Anyone holding the token can read its payload, so never put secrets in a JWT.
Runs in your browser. Your files and text never leave your device - nothing is uploaded.
