← Passwords & security

Password / security tools

JWT decoder

Inspect a JWT header, payload and time claims locally, without signature verification.

Runs in your browser

Decoded data is unverified. This tool does not verify the signature, issuer or audience and must not be used to authenticate a token.

A three-part JWT, up to 64 KiB. Encrypted five-part JWE tokens are not supported.

Header and payload are decoded locally as JSON. No token is sent to a server or stored by this tool. Clear the input when you finish, especially on a shared device.