Security & Hashing

JWT Decoder

Inspect the readable parts of a JSON Web Token locally. Decoding does not verify its signature or prove the token is trustworthy.

Decoded header and payload
Your result will appear here.
Processed locally in this browser. Your input is not sent to DevKitly.

What is JWT Decoder?

A JWT has three Base64URL parts separated by dots: header.payload.signature. The header names the signing algorithm, the payload holds claims such as sub, iat, and exp, and the signature lets the server prove the token was not altered. This tool decodes the first two parts; it does not check the signature.

How to use JWT Decoder

  1. Paste your input into the editor above, or select Sample to load an example.
  2. Select Decode JWT. If the input cannot be processed, a message explains what to fix.
  3. Use Copy or Download to take the result with you, and Clear to start again.

Example

Input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiQWRhIn0.signature

Output

{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sub": "123",
    "name": "Ada"
  },
  "warning": "Decoded only. Signature not verified."
}

Practical use cases

  • Debug token claims
  • Check expiry timestamps
  • Inspect authentication payloads

Common problems

  • Confusing decoding with verification
  • Sharing live access tokens
  • Trusting claims before signature validation

Frequently asked questions

Is it safe to paste a production token?

Decoding happens locally and the token is not sent anywhere by DevKitly. Still, treat live tokens as credentials and prefer expired or test tokens.

Can anyone read my JWT payload?

Yes. Standard JWTs are signed, not encrypted. Never put secrets in the payload.

Is JWT Decoder free to use?

Yes. JWT Decoder is free and does not require an account.

Does my input leave the browser?

No. This tool performs its processing locally in your browser and does not need to upload your input.