Savvy Goose
Character Counter Text & Writing
Case Converter Text & Writing
Diff Viewer Text & Writing
Markdown Converter Text & Writing
Percentage Calculator Numbers & Time
Unit Converter Numbers & Time
Timestamp Converter Numbers & Time
Time Between Dates Numbers & Time
Barcode Generator Generators
QR Code Generator Generators
Base64 Encoder Data & Encoding
Image to Base64 Data & Encoding
URL Encoder Data & Encoding
JWT Decoder Data & Encoding
Hash Generator Data & Encoding
Color Converter Data & Encoding
JSON Formatter Data & Encoding
Format Converter Data & Encoding
Regex Tester Data & Encoding
Browser Info Data & Encoding
Password Generator Generators
Passphrase Generator Generators
UUID Generator Generators
Favicon Generator Generators
Image Resizer Generators
Slug Generator Generators
Lorem Ipsum Generators
Mermaid Editor Diagrams
Cron Expression Generator Developer Tools
GitHub Dependency Starrer Developer Tools
No results found
Buy me a coffee
Savvy Goose

JWT Decoder

Inspect a JSON Web Token's header and payload. No signature verification.

Token
Anatomy of a JWT

A JWT is three Base64url-encoded segments joined by dots:

header.payload.signature

  • Header: algorithm & token type.
  • Payload: the claims (who, what, when).
  • Signature: proves the token wasn't tampered with.

This tool only decodes. It doesn't verify the signature. Decoding requires no secret; verifying does.

Decoding only. We never verify the signature. Anyone holding the secret could mint a token that decodes the same way.
Header

Paste a token to see its header.

Payload

Paste a token to see its payload.

Signature

(none)

Share
The URL below carries the token. Be careful — anyone with the URL sees the token.

Token is too long to include in the URL.

Share URL

Anyone with this link can read the values it contains. Do not use it for sensitive data.

How to use the JWT Decoder

  1. Paste a JWT.
  2. See the decoded header and payload, plus expiry status.

Frequently asked questions

Does this verify the signature?
No, it only decodes the token. Verifying the signature needs the issuer's key.
Are tokens uploaded?
Decoding happens locally. Tokens can also appear in the optional share URL, so avoid sharing sensitive or production credentials.

Made for free with