JWT Decoder
Decode a JSON Web Token’s header and payload — no signature verification.
This only decodes the token — it does not verify the signature. A decoded payload is not proof the token is authentic or hasn't been tampered with; that check has to happen server-side against the secret or public key.
Decoding happens entirely in your browser. Your token is never sent to a server.
Header
{ "alg": "HS256", "typ": "JWT" }
Payload
{ "sub": "1234567890", "name": "John Doe", "iat": 1516239022 }
Signature (not verified)
SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
For informational and educational purposes only — not professional or technical advice, and not a substitute for consulting a qualified professional about your specific situation. TrueMeasureKit is not liable for decisions made based on these results. See our Terms of Service.
What's actually inside a JWT
A JSON Web Token is three base64url-encoded parts joined by dots: a header (which algorithm signed it), a payload (the actual claims — user ID, expiry, permissions), and a signature. Only the signature is cryptographically protected — the header and payload are just encoded, not encrypted, so anyone who intercepts a token can read its contents exactly like this tool does. That's precisely why the signature matters: it's what stops someone from editing the payload (say, changing a user role) and having the server accept the tampered token as legitimate.
Frequently asked questions
Does decoding a JWT verify that it's legitimate?
No — this tool decodes the header and payload only, which is just Base64 decoding and requires no secret key. It does not verify the signature, so a decoded token could have been tampered with; verification requires the issuer's actual signing key.
Is it safe to paste a real JWT into a web tool?
This runs entirely in your browser and never sends the token to a server, so it's safe from that angle — but a JWT payload can contain sensitive claims, so avoid pasting tokens into tools you don't trust to be fully client-side.