What is a JWT?
A JSON Web Token has three Base64URL-encoded parts: header, payload, and signature. This tool decodes the first two so you can inspect claims — it does not verify the signature.
Paste a JWT to instantly decode its header and payload as readable JSON.
Paste the value to encode or decode.
Pick the direction / algorithm if the tool has modes.
Copy the output. Decoding is not the same as verifying a signature.
A JSON Web Token has three Base64URL-encoded parts: header, payload, and signature. This tool decodes the first two so you can inspect claims — it does not verify the signature.
Use JWT Decoder to transform encodings in your browser. If you decode a JWT or similar token, that does not prove the signature is valid.
Watch for padding and character-set issues. Never paste production secrets into a shared screen.
Whenever possible, JWT Decoder processes your data locally with JavaScript in this page. That means drafts, secrets, and unfinished work stay on your device by default. Prefer this workflow when you do not want to upload sensitive text, tokens, passwords, or files to a third-party service.
No, this tool only decodes and displays the header and payload; it does not verify the signature or trust the token.
No, decoding happens entirely in your browser using JavaScript.
For most FlyUtils tools, no. Processing happens in your browser with JavaScript. If a tool ever needs a server, that will be stated clearly on the page.
Yes. JWT Decoder is free, with no sign-up and no artificial usage caps for normal personal and work use.
Yes. The page is mobile-first, so you can paste input, tweak options, and copy results from a phone or tablet.