Security Tool
JWT Debugger
Decode and inspect JSON Web Tokens. No data leaves your browser - everything is decoded client-side using standard base64 decoding.
Paste a JWT to get started
Or try the sample token to see how the debugger works.
Client-Side Only
All decoding runs entirely in your browser using standard base64 decoding. No tokens are ever sent to any server.
Inspection Only
This tool decodes tokens for inspection. It does not verify signatures. Never trust a JWT without server-side verification.
About JSON Web Tokens
- Header contains the signing algorithm (e.g. HS256, RS256) and token type
- Payload contains claims - statements about the user and metadata
- Signature verifies the token was not tampered with (requires the secret key)
- exp, iat, and nbf are standard time-based claims stored as Unix timestamps