How to use JWT Decoder
Inspect JWT header and payload locally without verifying its signature. Header and payload are decoded locally. The signature, issuer, audience and expiration are not verified. Never use decoded claims as an authorization decision.
- Set Input.
- Run the tool, review the result and its stated limitations, then copy or download if needed.
Example & practical use
Inspect JWT header and payload locally without verifying its signature. The example below demonstrates Input.
Example input:
{
"text": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.signature"
}
Expected result (relevant fields):
{
"header": {
"alg": "HS256"
},
"payload": {
"sub": "123"
},
"signatureVerified": false
}Features & result limitations
Header and payload are decoded locally. The signature, issuer, audience and expiration are not verified. Never use decoded claims as an authorization decision.
Frequently asked questions
What inputs does JWT Decoder accept?
Input
How should I interpret the JWT Decoder result?
Header and payload are decoded locally. The signature, issuer, audience and expiration are not verified. Never use decoded claims as an authorization decision.
Where does JWT Decoder process my data?
Inputs are processed locally in your browser. Submitted text is not sent to external services. A successful-run event increments an aggregate tool counter without your input.