// how it works
JWTs are three base64url-encoded segments separated by dots:
header.payload.signature. This tool splits on the dots,
base64url-decodes the first two segments, parses them as JSON, and renders
them as formatted text. The signature is shown as-is; verifying it would
require the issuer's secret or public key.
Everything runs in your browser via a small jwt-decoder.js file.
Nothing is sent to a server. You can confirm by viewing the source of this
page or watching the network tab in DevTools while you paste a token.
Because the decoding happens locally, you can use this with whatever tokens you'd otherwise be hesitant to paste into a third-party web form: internal service tokens, prod tokens covered by company policy, anything under NDA.
What this tool does NOT do:
- Signature verification: verifying a signature requires the secret (HS256) or public key (RS256/ES256). Verify in your application code or via a CLI tool you trust with secrets.
- Editing / re-signing: same reason. Use a JWT library
in your language of choice (e.g.
jose,PyJWT).
What it DOES do: decode header, decode payload, show the signature as
base64url (so you can compare it to expected), label standard claims
(iss, sub, aud, exp, etc.)
with human-readable names, convert exp/nbf/iat
timestamps to ISO time + relative ("3 days ago"), and flag whether the token
is expired.
Related: need to base64-encode arbitrary text or files instead? The Base64 Encoder & Decoder handles UTF-8 text plus file-to-base64 with data-URL output.
// a free, browser-only tool by Tiempo Software, built in Omaha, Nebraska. Runs entirely in your browser; nothing you enter is uploaded. see all tools.