JWT Decoder
Decode JSON Web Tokens locally - header, payload and expiry, nothing sent anywhere.
About this tool
Decode a JWT online without the security risk: pasting tokens into random websites can leak credentials, but this decoder runs entirely in your browser. See the header, payload claims and expiration date instantly. Signature verification is not performed.
Does decoding verify the token signature?
No - decoding only reads the Base64 payload. Verifying requires the secret or public key and should happen server-side.
Is pasting a JWT here risky?
Unlike most online decoders, this one runs locally, so the token never leaves your machine.