JWT Decoder

Read what is inside a JSON Web Token — the header, the payload and when it expires. Decoded in your browser, and the signature is never checked. Your file never leaves this page. Everything happens in your browser, and there is no upload endpoint to send it to — that is checked by a build gate that fails if any network code reaches a tool’s bundle.

How to do it

  1. Paste your token. A Bearer prefix is fine.
  2. Read the header and payload.
  3. Check the notes underneath for anything worth knowing.

Questions

Does this verify the token?

No, and it never will. Verifying a signature requires the issuer’s secret or public key. This page does not ask for one and you should not paste a signing secret into any web page. What you get here is the contents, which are only encoded, not encrypted.

Is it safe to paste a token here?

The token never leaves your browser — there is no upload and no server to receive it. That said, a token is a credential: if it is a live one from production, treat it with the same care you would a password.

What does “alg: none” mean?

It means the token is unsigned. It is a legal value in the specification and the basis of a well-known authentication bypass — a server that trusts it will accept a token anybody wrote. If you see it on a real token, that is worth investigating.

Why can it not read my token?

If it has five parts rather than three, it is a JWE — an encrypted token — and its contents cannot be read without the decryption key.

Related tools

Browse every tool