A JWT (JSON Web Token) is a compact, URL-safe token made of three Base64URL-encoded parts separated by dots: a header describing the signing algorithm, a payload holding the claims (user id, roles, expiration, etc.), and a signature. This tool decodes the header and payload back into readable JSON, entirely in your browser — the token never leaves your machine.
This is decoding, not verification. Anyone can decode a JWT's contents, since the header and payload are only Base64-encoded, not encrypted. Verifying the signature requires the issuer's secret or public key, which this tool does not have and does not ask for.
JWTs are commonly used for authentication and authorization in web APIs. The exp (expiration) and iat (issued at) claims, when present, are shown above as human-readable dates.
Does decoding a JWT verify its signature?
No — this tool only decodes the header and payload (both are just Base64URL-encoded JSON, readable by anyone); it does not verify the signature, which requires the issuer's secret or public key.
Is it safe to paste a real JWT here?
The token is decoded entirely in your browser and never sent anywhere, but a JWT often contains sensitive claims, so avoid pasting production tokens into any third-party tool as a general practice.
Why can anyone read a JWT's contents?
The header and payload are only Base64URL-encoded, not encrypted — the signature protects against tampering, not against reading, so JWTs should never carry secrets.