JWT Decoder

Decode JWTs locally, inspect claims, and optionally verify HMAC signatures in the browser.

Input

Private by design: your JWT never leaves your device. Decoding does not make it valid or trustworthy.

Decoded does not mean verified. Do not paste production private keys.

Decoded parts

Paste a JWT and decode it.

Typ

-

Decode

-

Signatur

-

Claims

-

Paste a JWT and decode it.

Claims

No claims decoded.

Good to know

The JWT decoder breaks a JSON Web Token into header and payload directly in your browser, without automatically claiming trust in the signature. An HMAC signature can optionally be verified locally with a secret and an explicit algorithm allowlist, to guard against algorithm-confusion attacks.

Typical searches include JWT decoder, show JWT payload, and inspect bearer token. You can also check the expected issuer, audience, and subject, plus a list of required claims, and a leading “Bearer ” prefix is optionally stripped automatically. Important: decoded does not mean verified — a token's authenticity must be validated separately, and production private keys or secrets should not be pasted here.

Typical use cases

Inspect an API token's payload while debugging

Paste a bearer token directly — the leading “Bearer ” prefix is optionally stripped automatically — and check claims such as exp, iss, or custom fields.

Trace an HMAC signature of a test token locally

Enter a test secret and an algorithm allowlist to check whether the HMAC signature of a self-generated token is correct.

Tips for better results

Never paste production secrets

The HMAC secret field is only meant for local tests — never paste production private keys or signing secrets.

Deliberately restrict the algorithm allowlist

Explicitly restrict the allowed algorithms to the expected value, to prevent a manipulated header algorithm from being accepted.

How it works

Step by step

  1. 1

    Paste the JWT

    Paste the JWT, with or without a leading “Bearer ” prefix.

  2. 2

    Optionally check claims and signature

    Enter expected claims or an HMAC secret with an algorithm allowlist, if needed.

  3. 3

    Copy the header and payload

    Copy the decoded parts as JSON or download them as a file.

Features

Optional HMAC verification

Verify HMAC signatures locally with a secret and an explicit algorithm allowlist.

Claim checks

Check the expected issuer, audience, subject, and a list of required claims.

Local processing

Your JWT never leaves your device; decoding runs entirely in the browser.

Frequently asked questions

Does decoded mean the token is valid?

No. Decoding only shows the content; authenticity must be validated separately with signature verification, a key, or a certificate.

Should I paste production secrets for verification?

No. Use the secret field only for local tests, never for production private keys or signing secrets.

More tools