JWT Decoder Online

Paste a JSON Web Token to decode the header and payload, inspect claims, and understand what is inside the token without uploading it.

jwt decodeJSON Web TokenNo upload
Paste a token with header.payload.signature format.

Inspect a JWT without trusting its claims

  1. Paste a sample token that contains no live credentials.
  2. Inspect the decoded header and payload.
  3. Use a trusted server-side library and the issuer’s key to verify any token used for authentication.

Example and limits

JWT payloads are usually encoded, not encrypted. Anyone who obtains such a token may be able to read its claims. Never include a live token in a bug report or public screenshot.

Does decoding verify the token?

No. Decoding does not prove the signature, issuer, audience, or validity period. Do not use this page’s decoded output as an authorization decision.