Skip to content
PrivateDevTools
100% Local — Your data never leaves your browser

JWT Decoder

Decode JWT headers and payloads locally with Base64URL parsing. Signatures are not verified and tokens never leave your device.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsInJvbGUiOiJhZG1pbiIsImlhdCI6MTcxNjIzOTAyMiwiZXhwIjoxOTE2MjM5MDIyfQ.v8m7BQ-J8BrptOS3GygfdwaGq3ftKEzX3UkK9hcfFqU

Signature is shown but not verified — verification requires your secret or public key.
Header
{
  "alg": "HS256",
  "typ": "JWT"
}
Payload
{
  "sub": "1234567890",
  "name": "Ada Lovelace",
  "role": "admin",
  "iat": 1716239022,
  "exp": 1916239022
}
Timestamps
Expires exp
2030-09-21T16:37:02.000Z
Issued at iat
2024-05-20T21:03:42.000Z

How it works

JSON Web Tokens are compact, URL-safe strings with three Base64URL segments: header, payload, and signature. This decoder splits the token, Base64URL-decodes the first two segments, and pretty-prints the resulting JSON so you can inspect claims such as iss, sub, aud, exp, and custom application fields. Signature verification is intentionally omitted—cryptographic validation needs your secret or public key and usually belongs in your auth stack, not a paste tool. By avoiding verification libraries and network calls, the page stays lightweight and keeps confidential tokens on-device. Treat decoded output carefully: JWTs often contain personally identifiable information. Clear the field when finished. If decoding fails, check for missing segments, incorrect padding, or non-JWT strings. Use this tool for debugging middleware, correlating claim names, and confirming expiration timestamps during local development.

Frequently asked questions

Do you verify the JWT signature?

No. The tool only decodes header and payload for inspection. Verification must happen in your application.

Is it safe to paste production tokens?

Processing is local, but anyone with screen access can see claims. Prefer non-production tokens when possible.

Why is my token invalid?

JWTs need three Base64URL parts separated by dots. Truncated tokens or URL-encoded payloads often fail.

Are tokens stored?

No remote storage. Content lives only in memory for the page session unless you copy it elsewhere.