JWT Decoder

Paste a JWT to decode its header and payload. Optionally verify the signature with your secret or public key.

Home/Tools/JWT Decoder
Loading…

How to Decode a JWT

  1. Paste your JWT token into the input area
  2. The header and payload are decoded and displayed immediately
  3. Optionally enter your secret or public key to verify the signature — the tool will show Signature Verified or Invalid Signature

Is my data safe?

Yes. Everything runs 100% in your browser via the Web Crypto API. No tokens, secrets, or keys are ever sent to any server.

Can I decode without the secret?

Yes. The header and payload are only Base64URL-encoded, not encrypted. You can always decode them — the secret is only needed to verify the signature.

FAQ

What is a JWT token?

A JSON Web Token (JWT) is a compact, URL-safe string used to transmit claims between parties. It has three Base64URL-encoded parts separated by dots: a header (algorithm and token type), a payload (claims such as user ID and expiry), and a signature.

Can I decode a JWT without the secret key?

Yes. The header and payload are only Base64URL-encoded, not encrypted. You can always read their contents without the secret. The secret is only needed to verify the signature.

Is it safe to paste a JWT token here?

Yes. All decoding and verification runs entirely in your browser via the Web Crypto API. No tokens, secrets, or keys are ever sent to any server.

Which signature algorithms are supported?

HS256, HS384, HS512, RS256, RS384, RS512, ES256, ES384, ES512, PS256, PS384, PS512, and EdDSA.

Why does my JWT show “Signature not verified”?

Signature verification is optional. If you have not entered a secret or public key, the tool shows the decoded header and payload but skips verification. Enter your key in the verification section to check the signature.