JWT Analyzer

Decode JWT header and payload, review claims, issuer, audience and expiry, verify signatures and flag suspicious configuration — all in your browser.

JWT input
Decoding runs entirely in your browser — the token never leaves this device.
What is a JWT?
A JSON Web Token has three base64url segments: a header describing the signing algorithm, a payload of claims, and a signature. The payload is encoded, not encrypted — anyone holding the token can read every claim inside it.

Header

Algorithm and key hints (alg, kid, jku).

Payload

Claims: issuer, audience, subject, expiry, scopes.

Signature

Proof the claims were not modified in transit.