JWT Decoder
Decode JWTs locally, inspect claims, and optionally verify HMAC signatures in the browser.
Input
Private by design: your JWT never leaves your device. Decoding does not make it valid or trustworthy.
Decoded does not mean verified. Do not paste production private keys.
Decoded parts
Paste a JWT and decode it.
Typ
-
Decode
-
Signatur
-
Claims
-
Paste a JWT and decode it.
Claims
No claims decoded.
Good to know
Good to know
The JWT decoder breaks a JSON Web Token into header and payload directly in your browser, without automatically claiming trust in the signature. An HMAC signature can optionally be verified locally with a secret and an explicit algorithm allowlist, to guard against algorithm-confusion attacks.
Typical searches include JWT decoder, show JWT payload, and inspect bearer token. You can also check the expected issuer, audience, and subject, plus a list of required claims, and a leading “Bearer ” prefix is optionally stripped automatically. Important: decoded does not mean verified — a token's authenticity must be validated separately, and production private keys or secrets should not be pasted here.
Typical use cases
Inspect an API token's payload while debugging
Paste a bearer token directly — the leading “Bearer ” prefix is optionally stripped automatically — and check claims such as exp, iss, or custom fields.
Trace an HMAC signature of a test token locally
Enter a test secret and an algorithm allowlist to check whether the HMAC signature of a self-generated token is correct.
Tips for better results
Never paste production secrets
The HMAC secret field is only meant for local tests — never paste production private keys or signing secrets.
Deliberately restrict the algorithm allowlist
Explicitly restrict the allowed algorithms to the expected value, to prevent a manipulated header algorithm from being accepted.
How it works
How it works
Step by step
Features
Features
Optional HMAC verification
Verify HMAC signatures locally with a secret and an explicit algorithm allowlist.
Claim checks
Check the expected issuer, audience, subject, and a list of required claims.
Local processing
Your JWT never leaves your device; decoding runs entirely in the browser.
Frequently asked questions
Frequently asked questions
Does decoded mean the token is valid?
No. Decoding only shows the content; authenticity must be validated separately with signature verification, a key, or a certificate.
Should I paste production secrets for verification?
No. Use the secret field only for local tests, never for production private keys or signing secrets.
More tools
More tools
Base64 Decoder
Decode Base64, Base64URL, MIME Base64, or data URLs to bytes directly in the browser.
URL Decoder
Decode percent-encoded URL components, paths, query strings, and form data locally.
JSON Formatter
Validate, format, minify, analyze, and inspect JSON as a tree locally.
Base64 Encoder
Encode text or local files to Base64, Base64URL, MIME Base64, or data URLs directly in the browser.