🧰Locly

JWT Decoder (Runs Locally in Your Browser)

Decode JWT tokens to view header and payload data, processed locally in your browser

Note: This tool only decodes JWT tokens. It does NOT verify signatures.

About This Tool

JWT (JSON Web Token) is a compact, URL-safe token format used for securely transmitting information between parties. A JWT consists of three parts: Header (algorithm and token type), Payload (claims and data), and Signature. This tool decodes the Header and Payload sections to help you inspect token contents. Important: This is a decode-only tool - it does NOT verify JWT signatures. All processing is processed locally in your browser, and your token data is never uploaded to any server.

How to Use

  1. Paste your complete JWT token in the input field
  2. Click 'Decode' to parse the token
  3. View the decoded Header (algorithm, type) in the first output box
  4. View the decoded Payload (claims, expiration, custom data) in the second output box
  5. Use 'Copy' buttons to copy decoded JSON to clipboard

Common Use Cases

  • API debugging: Inspect JWT tokens returned by authentication endpoints
  • Token validation: Check token expiration time (exp claim) and issued time (iat)
  • Development testing: Verify token payload contains expected user data and permissions
  • Learning: Understand JWT structure and how claims are encoded
  • Troubleshooting: Debug authentication issues by examining token contents

FAQ

Q1: Is it safe to decode JWT tokens here?

Yes. All decoding happens locally in your browser using JavaScript. Your JWT token is never sent to any server. However, be cautious about sharing decoded token contents as they may contain sensitive information.

Q2: Why doesn't this tool verify signatures?

Signature verification requires the secret key or public key used to sign the token. Since this is a client-side tool and we don't have access to your signing keys, we can only decode the token contents. For signature verification, use your backend or a tool with access to your keys.

Q3: What do the three parts of a JWT mean?

Header: Contains algorithm (alg) and token type (typ). Payload: Contains claims - registered claims like exp (expiration), iat (issued at), sub (subject), plus any custom claims. Signature: Used to verify the token hasn't been tampered with (not shown in decoded output).

Q4: Can I edit and re-encode a JWT here?

No, this is a decode-only tool. Modifying a JWT would invalidate its signature. To create or modify JWTs, you need access to the signing key and should use appropriate server-side libraries.

Q5: What if my token shows 'Invalid JWT format'?

Ensure your token has exactly three parts separated by dots (header.payload.signature). Check for extra whitespace, missing characters, or incomplete copying. Valid JWTs are Base64URL encoded strings.

Related Tools