JWT decoder

Decodes a JSON Web Token's header and payload locally in your browser. Decoded does not mean verified.

1 · Input

Nothing is sent to a server - the token never leaves this browser tab, is never stored, and is never logged.


What this does

Splits a JSON Web Token into its three segments and decodes the header and payload from Base64URL - showing the algorithm, standard claims (iss, sub, aud), and iat/nbf/exp as readable times with expiry state.

Decoded does not mean verified

This never checks the signature - a JWT's payload is Base64URL-encoded, not encrypted, so anyone can decode it without a key. Verifying that a token was genuinely issued by who it claims requires the actual signing key, which this tool never asks for or has. A token with alg: none is flagged - never treat that as secure.

Privacy

The token never leaves this browser tab - it is not sent to a server, not stored, and not logged.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.

Add this tool to your website. Free, responsive, no ads, no sign-up - copy one line of code.

Embed this tool