JWT Decoder & Inspector
Decode JSON Web Tokens, inspect claims, payload, and expiry dates locally. Tokens never leave your browser.
Important Security Notice: This tool only decodes base64url-encoded headers and payloads. It does NOT verify the cryptographic signature or validate signature trust. Never share tokens containing private keys or credentials. All decoding is executed strictly inside your browser.
Encoded Token (Header.Payload.Signature)
0 characters0 segments
Invalid JWT Token
Please enter a JWT token
Standard JWT Claims
Common registered claims include sub (subject/user ID), iss (issuer authority), exp (expiration timestamp), and iat (issued at).
Base64URL Encoding
JWT segments are URL-safe base64 strings with + replaced by - and / replaced by _, omitting trailing padding equals signs.
Never Send Secrets Online
Unlike online decoders that proxy your tokens across remote servers, TextCraft executes all parsing purely in client memory, keeping session tokens completely confidential.