JWT Decoder

Paste a JSON Web Token to see what’s inside. Decoding happens entirely in your browser.

Runs in your browser — nothing is uploaded

How to use JWT Decoder

  1. Paste the token (the part after “Bearer ”).
  2. Read the decoded header, payload and time claims.

Questions

Does this verify the signature?

No. It only decodes the token. Anyone can read a JWT’s contents — signature verification needs the secret or public key and should happen on your server.

Is it safe to paste a real token?

The token is decoded locally and never sent anywhere. Still, treat live tokens like passwords.