JWT Decode Online — Header, Payload & Signature

Paste a JWT token to inspect its header and payload as formatted JSON. The signature is shown separately — we do not verify signatures or send your token to any server.

Loading…
JWT decode — inspect tokens locally
Decode JSON Web Token headers and payloads in your browser. Optional inline signature verify with secret (HMAC) or public key (RSA, RSA-PSS, ECDSA, EdDSA). JWKS and claim checks: jwt-verify.

How JWT decode works here

Paste the full token (three Base64URL segments separated by dots). Header and payload render as formatted JSON. Decoding updates automatically as you edit. Editors start empty — use **Load sample** or pick an algorithm to load a demo fixture. Optional verify compares the signature when you paste the signing secret or public key (algorithm-dependent). alg=none tokens decode as unsecured. For JWKS fetch, audience, or issuer checks use jwt-verify.

Privacy & limits

Tokens never leave your browser tab. We do not fetch remote JWKS keys or validate exp/nbf/aud claims in this debugger. Pair with jwt-encode for fixtures, or jwt-verify for full asymmetric trust policies.

Typical workflow

OAuth access token

Sample input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Expected output

Header shows alg/typ; payload shows sub, exp, scopes.

Debugging 401 errors

Sample input

Paste token from Network tab

Expected output

Check exp claim and issuer before blaming API routes.

Related encode utilities

To sign HS256 tokens for fixtures use jwt-encode. Encoding and decoding here do not verify trust — use your identity provider for that.

JWT decode FAQ

Decode ≠ verify

Does this verify signatures?

Optional inline verify for none (unsecured), HMAC (HS256/384/512), RSA (RS256/384/512), RSA-PSS (PS256/384/512), ECDSA (ES256/384/512), and EdDSA (Ed25519) — paste secret or public key. No JWKS fetch or exp/aud/iss claim checks here. For those use jwt-verify. Decoding alone never proves authenticity.

Is my token sent to FastMinify?

Never — decoding runs entirely in your browser.

Can I paste refresh tokens safely?

Processing stays local, but treat tokens as secrets — avoid screen sharing and clear the field when done.

Encode or decode Base64, URL components and HTML entities — client-side only.