Security Tools

JWT Decoder

Decode and inspect JWT (JSON Web Token) tokens - see the header, payload, and signature broken out as readable JSON, without needing to trust a third-party service with your token.

This tool only decodes the JWT. It does not verify the signature. Never paste sensitive production tokens into online tools.

How do you decode a JWT?

A JWT has three dot-separated parts - header, payload, and signature - and the first two are Base64URL-encoded, not encrypted. Decoding reveals the claims in plain text. Anyone holding the token can read its payload, so never put secrets in a JWT.

Runs in your browser. Your files and text never leave your device - nothing is uploaded.