JWT Header and Payload Decoder
Received a JWT from an API and want to inspect it? This decoder converts Base64Url sections into readable text in your browser. Review expiry, user ID and roles during development. Limit: it only decodes, it does NOT verify the signature.
Step by step
- Copy a JWT from your test environment.
- Paste all three dot-separated parts.
- Check alg and typ in the header.
- Review role and exp in the payload.
- Compare with backend logs, verify server-side.
Example scenario
Paste a development token and review header plus payload. Check the expiry timestamp and role spelling. The signature part is shown only as a carrier. This spots missing claims before backend changes.
Check your result
Compare exp claims with current time. Alter one signature character and notice content still decodes, proving no verification. Validate with a server library.
Frequently asked questions
Verifies signature?
No, decodes only.
Paste production tokens?
Not recommended; use expired test tokens.
Why is exp a number?
It is a Unix timestamp; convert it.
Invalid looking?
Check for three parts; clean spaces.
Open the tool: JWT header and payload decoder →
Keep an original copy before processing your file. Examples are illustrative; results depend on your document.