Inspect claims
Decode sub, aud, exp, and custom claims
Readable payload JSON
Inspect JWT headers and payloads without uploading tokens.
Quick answer
A JSON Web Token usually contains a Base64URL-encoded header, payload, and signature separated by periods.
Decoding does not verify the token signature or prove that the token is trustworthy.
Decoded token
The header and payload will appear here.
Illustrative view
Only encoded content is decoded; the signature is not verified.
A JSON Web Token usually contains a Base64URL-encoded header, payload, and signature separated by periods. This tool decodes the first two parts into readable JSON.
Decoding is not verification. Never trust claims until the signature, issuer, audience, and expiration have been validated by your application.
Decode sub, aud, exp, and custom claims
Readable payload JSON
Decode the token header
Algorithm and token type
No. It only decodes readable content and makes no trust or authenticity claim.
The tool runs locally, but sensitive live credentials should still be handled according to your security policy.
No. This tool runs locally in your browser, so the values or files you provide are not sent to a ToolStack server.
Keep going