Developer tool
Decode a JWT Header and Payload
Inspect the Base64URL-encoded header and payload of a JSON Web Token without verifying its signature.
Runs locally in your browser
Your text is not uploaded.
Simple steps
How it works
- 01
Paste a JWT with three dot-separated segments.
- 02
Decode the header and payload locally.
- 03
Review the claims and copy the readable JSON.
Good to know
Frequently asked questions
Does this tool verify a JWT signature?
No. It only decodes the header and payload; a valid-looking token may still be forged or expired.
Can I paste a production token?
Avoid pasting secrets into tools unless your security policy allows it. This page processes locally, but decoded text remains visible on screen.
What parts are decoded?
The first two JWT segments are decoded as Base64URL JSON. The signature is not checked.
What if the token is malformed?
The decoder reports missing segments, invalid Base64URL, or invalid JSON.
Is the token sent to a server?
No. Decoding occurs locally and makes no network request.