Skip to content
Runs privately in your browser

Free Online JWT Decoder

Inspect JWT header and payload locally without verifying its signature.

Your input stays on this device. Processing is bounded; regex runs in a worker with a two-second timeout.

Result

How to use JWT Decoder

Inspect JWT header and payload locally without verifying its signature. Header and payload are decoded locally. The signature, issuer, audience and expiration are not verified. Never use decoded claims as an authorization decision.

  1. Set Input.
  2. Run the tool, review the result and its stated limitations, then copy or download if needed.

Example & practical use

Inspect JWT header and payload locally without verifying its signature. The example below demonstrates Input.

Example input:
{
  "text": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.signature"
}
Expected result (relevant fields):
{
  "header": {
    "alg": "HS256"
  },
  "payload": {
    "sub": "123"
  },
  "signatureVerified": false
}

Features & result limitations

Header and payload are decoded locally. The signature, issuer, audience and expiration are not verified. Never use decoded claims as an authorization decision.

Frequently asked questions

What inputs does JWT Decoder accept?

Input

How should I interpret the JWT Decoder result?

Header and payload are decoded locally. The signature, issuer, audience and expiration are not verified. Never use decoded claims as an authorization decision.

Where does JWT Decoder process my data?

Inputs are processed locally in your browser. Submitted text is not sent to external services. A successful-run event increments an aggregate tool counter without your input.

Learn more