Security Tool

JWT Debugger

Decode and inspect JSON Web Tokens. No data leaves your browser - everything is decoded client-side using standard base64 decoding.

Paste a JWT to get started

Or try the sample token to see how the debugger works.

Client-Side Only

All decoding runs entirely in your browser using standard base64 decoding. No tokens are ever sent to any server.

Inspection Only

This tool decodes tokens for inspection. It does not verify signatures. Never trust a JWT without server-side verification.

About JSON Web Tokens

  • Header contains the signing algorithm (e.g. HS256, RS256) and token type
  • Payload contains claims - statements about the user and metadata
  • Signature verifies the token was not tampered with (requires the secret key)
  • exp, iat, and nbf are standard time-based claims stored as Unix timestamps