JWT Decoder
Decode JWT header and payload without a secret. Inspect claims and expiration client-side.
Last updated July 1, 2026
Prove it runs locally
- Open DevTools → Network tab
- Click Generate
- Confirm zero outbound requests for the secret
Generation uses crypto.getRandomValues() in your browser. Privacy policy
How to Use This Tool
Paste your JWT token into the input field. The tool immediately decodes the Base64URL-encoded header and payload — no secret required.
Review the decoded JSON for algorithm (alg), expiration (exp), subject (sub), and other claims.
Optionally enter your HS256 secret to verify the signature. For full validation workflows, use the JWT Validator. CLI decode snippets (without verify) are available below the widget.
Never paste production tokens on shared machines. All decoding happens in your browser.