Tool

JWT Decoder

Decode JWT header and payload without a secret. Inspect claims and expiration client-side.

Last updated July 1, 2026

Runs entirely in your browser — no data sent to servers. Privacy policy
Prove it runs locally
  1. Open DevTools → Network tab
  2. Click Generate
  3. Confirm zero outbound requests for the secret

Generation uses crypto.getRandomValues() in your browser. Privacy policy

Advertisement

How to Use This Tool

Paste your JWT token into the input field. The tool immediately decodes the Base64URL-encoded header and payload — no secret required.

Review the decoded JSON for algorithm (alg), expiration (exp), subject (sub), and other claims.

Optionally enter your HS256 secret to verify the signature. For full validation workflows, use the JWT Validator. CLI decode snippets (without verify) are available below the widget.

Never paste production tokens on shared machines. All decoding happens in your browser.

Continue learning