100% private. Decoding happens entirely in your browser — your token is never sent anywhere. Decoding is not verification: always verify signatures server-side.
Developer / Code
Decode a JSON Web Token
Paste a JWT (three base64url segments separated by dots) to read its header and payload claims.
Decoded token
Paste a token and press Decode.
Header
Payload
When NOT to use JWT Decoder
- Never trust a token just because it decodes — decoding is not verification, and an attacker can craft any payload they like.
- Encrypted tokens (JWE, five segments) cannot be decoded without the key — this tool handles signed JWTs (three segments) only.
Questions people ask
Is my input sent to a server?
No. This tool runs entirely in your browser using JavaScript. Nothing you paste is uploaded, stored, or sent anywhere.
Is it safe to paste a token here?
Yes — decoding happens entirely in your browser with JavaScript; the token never leaves your device. As a general rule, still avoid pasting production tokens into any tool you don't control.
Does it verify the signature?
No. This tool decodes the header and payload only. A decoded token proves nothing about authenticity — always verify signatures server-side with the issuer's keys.
Related tools
Share this tool
Found it useful? Share it with someone who needs it — the tool is free and runs entirely in the browser.