JWT Decode Online — Header, Payload & Signature

Paste a JWT token to inspect its header and payload as formatted JSON. The signature is shown separately — we do not verify signatures or send your token to any server.

Loading…
JWT decode — inspect tokens locally
Decode JSON Web Token headers and payloads in your browser. Optional inline signature verify with secret (HMAC) or public key (RSA, RSA-PSS, ECDSA, EdDSA). JWKS and claim checks: jwt-verify.

How JWT decode works here

Paste the full token (three Base64URL segments separated by dots). Header and payload render as formatted JSON. Decoding updates automatically as you edit. Editors start empty — use **Load sample** or pick an algorithm to load a demo fixture. Optional verify compares the signature when you paste the signing secret or public key (algorithm-dependent). alg=none tokens decode as unsecured. For JWKS fetch, audience, or issuer checks use jwt-verify.

Privacy & limits

Tokens never leave your browser tab. We do not fetch remote JWKS keys or validate exp/nbf/aud claims in this debugger. Pair with jwt-encode for fixtures, or jwt-verify for full asymmetric trust policies.

Typical workflow

OAuth access token

Sample input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Expected output

Header shows alg/typ; payload shows sub, exp, scopes.

Debugging 401 errors

Sample input

Paste token from Network tab

Expected output

Check exp claim and issuer before blaming API routes.

Related encode utilities

To sign HS256 tokens for fixtures use jwt-encode. Encoding and decoding here do not verify trust — use your identity provider for that.

JWT decode FAQ

Decode ≠ verify

Does this verify signatures?

Optional inline verify for none (unsecured), HMAC (HS256/384/512), RSA (RS256/384/512), RSA-PSS (PS256/384/512), ECDSA (ES256/384/512), and EdDSA (Ed25519) — paste secret or public key. No JWKS fetch or exp/aud/iss claim checks here. For those use jwt-verify. Decoding alone never proves authenticity.

Is my token sent to FastMinify?

Never — decoding runs entirely in your browser.

Can I paste refresh tokens safely?

Processing stays local, but treat tokens as secrets — avoid screen sharing and clear the field when done.

Encoding

Encode or decode Base64, URL components and HTML entities — client-side only.

Explore other tool categories

Minify

Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.

Beautify

Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.

Unminify

Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.

Conversion

Transform data between JSON, YAML, XML and CSV locally — no server uploads.

CSS preprocessors

Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.

JSON Tools

Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.

SVG Tools

Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.

DevOps & Infra

Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.

CI/CD

GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.

Logs & observability

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.

Kubernetes

Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.

Networking / IP

CIDR, subnets, and IPv4/IPv6 helpers — in your browser.

Security & tokens

JWKS, X.509 certificates, and secrets scan — browser-local.

API & schemas

OpenAPI tools to format, validate, and lint your specs.

Developer utilities

Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.

Text & Markdown

Count words, build Markdown TOCs, and clean line lists — all in your browser.

AI & LLM

Token counting, pricing estimates, and context-window fit — 100% browser-local.

Serialization

Serialize and deserialize PHP data structures beside JSON workflows.