JWT Decoder

Parse and decode JSON Web Tokens securely in your browser.

Waiting for valid token...
Waiting for valid token...

About JSON Web Tokens (JWT)

A JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is used as the payload of a JSON Web Signature (JWS) structure or as the plaintext of a JSON Web Encryption (JWE) structure.

How to Use

  1. Paste: Simply paste your encoded JWT (a string containing three dot-separated Base64-URL strings) into the left text area.
  2. View Output: The decoder instantly parses the token, splitting it into its readable Header and Payload JSON structures.
  3. Copy: Use the copy buttons to extract the raw JSON data for debugging.

Structure of a JWT

  • Header: Typically consists of two parts: the type of the token (JWT) and the signing algorithm being used (e.g., HMAC SHA256 or RSA).
  • Payload: Contains the claims. Claims are statements about an entity (typically, the user) and additional data.
  • Signature: Used to verify the message wasn't changed along the way. (Note: This tool decodes the token; it does not verify the signature against a secret key.)

FAQ

Is it safe to decode my tokens here?

Yes. All decoding runs entirely in your web browser. No data is sent to a server or recorded.

Can I edit the JWT and re-encode it?

This specific tool is designed only for decoding and reading existing tokens. Re-encoding typically requires access to a private signing key.