Developer tool

Decode a JWT Header and Payload

Inspect the Base64URL-encoded header and payload of a JSON Web Token without verifying its signature.

Decode only. This tool does not verify token signatures.

Runs locally in your browser

Your text is not uploaded.

Simple steps

How it works

  1. 01

    Paste a JWT with three dot-separated segments.

  2. 02

    Decode the header and payload locally.

  3. 03

    Review the claims and copy the readable JSON.

Good to know

Frequently asked questions

Does this tool verify a JWT signature?

No. It only decodes the header and payload; a valid-looking token may still be forged or expired.

Can I paste a production token?

Avoid pasting secrets into tools unless your security policy allows it. This page processes locally, but decoded text remains visible on screen.

What parts are decoded?

The first two JWT segments are decoded as Base64URL JSON. The signature is not checked.

What if the token is malformed?

The decoder reports missing segments, invalid Base64URL, or invalid JSON.

Is the token sent to a server?

No. Decoding occurs locally and makes no network request.