โ All tools
JWT Decoder & Analyzer
Paste a token to read its header, payload and claims, with reminders about weak algorithms and expiry. Everything stays in your browser.
Local decoder โ authorized tokens only.
JWTs often carry session identity. Decoding runs entirely in your browser; nothing is uploaded.
- Only inspect tokens issued to you or captured during authorized testing.
- A signature is not verified here โ decoding shows contents, not authenticity.
- Treat tokens as secrets; clear the field when done on a shared machine.
1. Paste a JWT
2. Decoded
Header
โ
Payload
โ
Signature (base64url, not verified)
โ
3. Claims & checks
Checks are heuristic reminders (alg, expiry, common weaknesses). See the JWT attacks cheat sheet for exploitation and the hardening checklist.