JWT Decoder

korinat.com

Decode JWT

Paste a JWT below and press Decode

Decode / Inspect only — not verify

This tool does not verify signatures, does not accept keys or JWKS, and never checks authenticity. Treat decoded claims as untrusted data.

Data never leaves the browser.

Paste a JSON Web Token or open a file

Header

Payload

Signature

Raw base64url segment — not verified.

Data never leaves the browser.

JWT Decoder

Decode and inspect JSON Web Tokens in your browser. Decode / Inspect only — not verify. Nothing is uploaded. Limit: 50 MB per file.

JWT parts

A JWT has three base64url segments separated by dots: Header, Payload, and Signature. This tool decodes Header and Payload as JSON and shows the Signature segment as raw base64url.

No signature verification

This is not a verifier. There is no key paste, no JWKS fetch, and no signature check. Decoded claims are untrusted inspection data only.

Privacy

Decoding runs on your device. There is no account, no upload, and no LocalStorage of your token. Closing the tab discards unsaved text.

What are the three JWT parts?

Header describes the token type and algorithm. Payload holds claims. Signature is the third base64url segment — shown raw here, never verified.

Does this verify the signature?

No. Decode / Inspect only. No keys, no JWKS, no authenticity check.

What are the exp / nbf / iat hints?

If those claims exist, the tool shows Europe/Berlin times from the local browser clock. That is a convenience hint, not a server promise.

Is my token uploaded?

No. Everything stays in the browser. Open, decode, copy, and save all run locally.