undelo

JWT Decoder

Decode a JWT's header and payload as formatted JSON

Decodes a JWT's header and payload into readable JSON — paste a token and both parts appear immediately, with a clear note that this only decodes, it doesn't verify the signature.

How it works

A JWT is three Base64URL-encoded segments separated by dots; this tool splits on those dots, decodes the header and payload segments (skipping the signature, since verifying it would need the secret or public key, which never appears client-side), and parses each as JSON for display.

Frequently asked questions

Does this verify that the token is genuine or hasn't expired?

No — it only decodes the header and payload so you can read their contents. A token that decodes cleanly here could still be forged, tampered with, or expired; verifying the signature requires the issuing secret or public key, which this tool never has.

Why did it say the token is malformed?

A JWT needs exactly three dot-separated, non-empty segments (header, payload, signature). Anything else — missing a segment, extra dots, or an empty segment — doesn't match that shape and is rejected before attempting to decode.

Why did it say the token has invalid JSON?

The header or payload segment decoded from Base64URL successfully, but what came out wasn't valid JSON — meaning the token's structure is broken beyond just being an unusual format for this tool to display.

Can I decode a token that uses a non-JSON payload?

No — this tool assumes the standard JWT structure, where both header and payload are JSON objects. Non-standard tokens with a different payload format aren't supported.

Is my token sent anywhere?

No — decoding happens entirely in your browser. Given that a JWT payload often contains user or session data, that matters: nothing here is uploaded or logged, even though this tool never touches the signature.