How to decode a JWT
- Paste the compact token only, without a Bearer prefix or surrounding quotes.
- Select Decode without verification.
- Inspect the header, payload, encoded signature and signature byte count.
- If you copy or download the result, remember it may contain the same sensitive claims as the original token.
The sample is an intentionally unsigned demonstration token. It is not an account credential and should not be used to test access to a service.
Header, payload and signature
A supported token has three dot-separated segments. The first two segments decode from Base64URL to UTF-8 JSON objects. The header describes fields such as the claimed algorithm; the payload contains claims. The signature segment is decoded only to inspect its byte length and is retained in its original encoded form.
The header must contain a nonempty string alg field. Its presence is not proof that the stated algorithm was used. A token claiming alg none may have an empty signature. The tool still displays an unverified result. Encrypted five-part JWE, detached payloads and non-JSON payloads are outside this decoder’s scope.
Decoding is not signature verification
Anyone can construct Base64URL-encoded JSON. Reading its fields therefore establishes neither the issuer nor whether someone changed it. Signature verification needs a trusted key, an allowed algorithm and the expected application context. This tool asks for no key and performs none of those checks.
Claim validation is another separate step: the recipient must evaluate issuer, audience, time conditions and any application rules. A decoded name or role must never become an authorization decision. The output explicitly says NOT VERIFIED and does not show a green “valid token” state.
An unsigned demonstration
Input
Header JSON: {"alg":"none","typ":"JWT"}
Payload JSON: {"sub":"demo","iat":1700000000}Result
Decoded header and payload objects Signature bytes: 0 Verification: NOT VERIFIED
Some registered time claims use NumericDate seconds from the Unix epoch. To inspect 1700000000, select seconds in the Unix Timestamp Converter; it represents 2023-11-14T22:13:20.000Z. Converting a time does not establish whether the claim should be trusted or accepted now.
Malformed tokens and decoding limits
The decoder rejects invalid Base64URL characters, impossible lengths, noncanonical padding bits and invalid UTF-8. JWT segments are expected to be unpadded. Both JSON objects are checked by the existing lossless parser, including duplicate-key rejection and the nesting limit. Large integer tokens remain intact instead of being rounded for display.
Input is limited to 64 KiB. Leading and trailing whitespace around the whole token is removed; whitespace inside segments is invalid. If the token has five parts, do not delete segments to make it fit: it may be encrypted. If a segment is an ordinary Base64 value unrelated to JWT, use the Base64 encoder and decoder instead. Use JSON Viewer for a larger decoded claim object you want to explore.
Processing and privacy
The operation runs in your browser. The tool does not send the material you enter to a processing server or automatically save it. Reset clears the form and result from the interface; it is not a secure-erasure guarantee for browser memory. Copy and download deliberately create copies outside the tool. The website itself still makes ordinary requests for its pages and scripts. See the privacy policy for the distinction.
Frequently asked questions
Can a decoded JWT still be forged or expired?
Yes. Decoding does not verify the signature, issuer, audience, expiry or any authorization policy.
Does this tool decrypt tokens?
No. It reads supported three-part compact JSON tokens; encrypted five-part JWE is not supported.
Why does the sample have no signature?
It uses alg none to demonstrate structure without presenting a real credential. Its output is explicitly unverified.