Skip to content
Technology·1 min read·

JWT decoder

Decode the header and payload of a JSON Web Token. The signature is shown as present or missing and is not checked.

The answer

A JWT is three Base64URL parts. This page decodes the header and the payload as JSON. It does not verify the signature, so a decoded payload is not proof the token is authentic.

Result

Payload

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Signature

Present, and not checked

What do you want to do next?

How this works

The first part is the header and the second is the payload. Both must be Base64URL-encoded JSON objects. The third part, when it is present, is reported as a signature that this page did not check.

Verification needs the issuer’s key and is a different task. Do not paste a live access token into a page you are about to share. The token would be in the address.

Practical steps

  1. 1

    Paste the token, including the dots.

  2. 2

    Read the payload claims such as exp or sub.

  3. 3

    Treat the result as decoded text, not as a verified login.

Examples

  • A sample token

    The payload includes the name and subject claims from the well-known example token. The signature is not checked.

Common mistakes

  • ×

    Sharing the page address after pasting a real access token. The token is in the query string.

Frequently asked questions

Does a successful decode mean the token is valid?

No. The signature was not checked. Anyone can change the payload and leave a fake signature.

What if there are only two parts?

The header and payload are still decoded, and the signature is reported as missing.

Sources