JWT Decoder
Decode and inspect JSON Web Tokens in your browser. Decode / Inspect only — not verify. Nothing is uploaded. Limit: 50 MB per file.
JWT parts
A JWT has three base64url segments separated by dots: Header, Payload, and Signature. This tool decodes Header and Payload as JSON and shows the Signature segment as raw base64url.
No signature verification
This is not a verifier. There is no key paste, no JWKS fetch, and no signature check. Decoded claims are untrusted inspection data only.
Privacy
Decoding runs on your device. There is no account, no upload, and no LocalStorage of your token. Closing the tab discards unsaved text.
What are the three JWT parts?
Header describes the token type and algorithm. Payload holds claims. Signature is the third base64url segment — shown raw here, never verified.
Does this verify the signature?
No. Decode / Inspect only. No keys, no JWKS, no authenticity check.
What are the exp / nbf / iat hints?
If those claims exist, the tool shows Europe/Berlin times from the local browser clock. That is a convenience hint, not a server promise.
Is my token uploaded?
No. Everything stays in the browser. Open, decode, copy, and save all run locally.