JWT Decoder
Inspect JSON Web Tokens (JWT) locally and securely. Paste your JWT below to decode its header and payload instantly, revealing claims and algorithms without any data leaving your browser.
Header
Paste a JWT below to see its decoded header.
Payload
Paste a JWT below to see its decoded payload.
Why use a local JWT Decoder?
Security researchers and API developers often need a trusted, local way to inspect opaque authentication tokens for debugging claims and algorithms without risking secret leakage to third-party servers. This JWT Decoder provides an immediate, client-side solution. A JWT (RFC 7519) is three Base64URL parts split by dots; this tool decodes the header and payload only — it never verifies the signature, ensuring your sensitive data remains private.
Understanding the structure and content of JWTs is crucial for both implementing secure authentication flows and identifying potential vulnerabilities. By decoding the header, you can see the cryptographic algorithm (`alg`) used, while the payload reveals critical claims like the subject (`sub`), issuer (`iss`), expiration time (`exp`), and other custom data, all without exposing your tokens to external services.
How to use this JWT Decoder
- Paste your complete JWT string into the input textarea in the bottom bar.
- The tool automatically detects the two dot separators and isolates segments 1 and 2.
- Review the structured Header and Payload cards to examine fields like `alg`, `kid`, `sub`, or `exp`.
- Switch to "Raw String" if you need the exact decoded bytes for hex or binary comparison.
- Click the copy icon on either card to export the claimed data for logging or testing.
FAQ
Q: How does this tool decode JWT claims?
A: It splits the token at the two dots, then applies Base64URL decoding (replacing `-` with `+` and `_` with `/`) followed by JSON.parse() strictly on RFC 7515 rules — no external APIs are contacted.
Q: Does this JWT decoder validate or verify the digital signature?
A: No. Per RFC 7519, signature verification requires access to the private key or public certificate and must be handled by your runtime; this tool deliberately skips it to avoid leaking secrets or triggering network calls.
Q: What should I do after decoding a timestamp claim like exp?
A: Convert any numeric expiration or issued-at (iat) seconds directly to human-readable dates using our Epoch Timestamp Converter for precise deadline tracking.
Q: Why do some decoded values contain underscores or hyphens?
A: JWTs use Base64URL encoding (RFC 7515 Section 3.2), which replaces + and / with `-` and `_` respectively and strips padding `=` signs for URL safety before reaching this decoder.