JWT Debugger & Decoder

Decode and inspect JSON Web Tokens (JWTs) in browser with header, payload, and signature views.

Quick Presets:

Encoded Token

header.payload.signature
Verify Signature (HS256)

Computed locally in browser via Web Crypto HMAC-SHA256.

Header: Algorithm & Token Type
// Decoded header will show here...
Payload: Data Claims
// Decoded payload will show here...
Signature
// Signature string

Frequently Asked Questions

What is a JSON Web Token (JWT)?

A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. It consists of three parts separated by dots: header, payload, and cryptographic signature.

Is it safe to paste JWTs into online tools?

This debugger runs 100% locally in your browser using the Web Cryptography API. Your tokens, secrets, and decoded payloads are never transmitted to any server.

How do I decode a JWT?

Paste your encoded token into the input field. The tool splits header, payload, and signature segments, decodes the base64url encoding, and formats JSON claims automatically.