Dev / JWT

Decode a JWT header and payload

Base64url decode only. Signature is not verified. There is no key server.

Last checked: September 2026. Confirm millimetres, pixels, and KB on the official form. Not a government website.

Runs in this tab. 0 uploads. MD5 is a checksum, not security.

Header and payload are decoded locally. Signature is not verified — there is no key server here.

{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sub": "1234",
    "name": "Cherry",
    "iat": 1516239022
  },
  "signature": "signature"
}

01

Drop

Drop the file. It stays in this browser tab.

02

Preset applied

Set the cap or preset for this job.

03

Download

Download from this device. Nothing is uploaded.

FAQ

Questions, answered

Verify signature?Open

No. Verification would need a key. We will not send the token anywhere to check it.

Is anything uploaded?Open

No. This tool runs in your browser tab. Close it and the data is gone.