โ† All tools

JWT Decoder & Analyzer

Paste a token to read its header, payload and claims, with reminders about weak algorithms and expiry. Everything stays in your browser.

Local decoder โ€” authorized tokens only. JWTs often carry session identity. Decoding runs entirely in your browser; nothing is uploaded.
  • Only inspect tokens issued to you or captured during authorized testing.
  • A signature is not verified here โ€” decoding shows contents, not authenticity.
  • Treat tokens as secrets; clear the field when done on a shared machine.

1. Paste a JWT

2. Decoded

Header

โ€”

Payload

โ€”

Signature (base64url, not verified)

โ€”

3. Claims & checks

Checks are heuristic reminders (alg, expiry, common weaknesses). See the JWT attacks cheat sheet for exploitation and the hardening checklist.