DEVELOPER · JWT
JWT decoder
Paste a JWT to inspect its header and payload clearly.
Paste a three-segment JWT/JWS to decode its header and payload locally. Common NumericDate claims are shown as readable times.
Local only · token is not storedDecoded ≠ Verified. This tool does not verify the signature, issuer, audience, key, or trustworthiness of the token.
Decode token
alg—
typ—
kid—
Signature segment—
Time claims
Security boundary
- The token is decoded locally and is never sent to a server or stored.
- A syntactically valid token may still be forged, expired, intended for another audience, or signed by an untrusted key.
- No secret cracking, JWKS fetching, automatic login, or signature-verification claim is provided.
Frequently asked questions
How do I use it?
Paste a token to inspect it.
Is anything uploaded?
Everything runs locally in your browser and is not uploaded.
How is this different?
Does not verify signatures—use your backend key flow for trust.