JWT Decoder
Decode JWT headers and payloads locally without exposing secrets.
Decode JWT tokens locally to inspect the header and payload without sending a token to a remote service.
What is this tool?
A JWT is a compact token format commonly used to carry identity and authorization data between systems. It consists of three parts: a header, a payload, and a signature. The header and payload are base64url-encoded, so they can be decoded and inspected by developers when debugging authentication flows or reviewing claims. Decoding a JWT does not verify the signature; it only reveals the token contents.
Example
Example token
Common JWT structure
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwidXNlcm5hbWUiOiJjYXNzaWRvciJ9.signature
Header
Token metadata
{
"alg": "HS256",
"typ": "JWT"
}Why use Cassidor?
- Helps inspect token claims directly in the browser.
- Useful for debugging authentication and authorization issues.
- Keeps token inspection local and transparent.
Frequently asked questions
What information can I see in a JWT?
You can inspect the decoded header and payload, which often include algorithms, claim names, and user or session metadata.
Does decoding verify a JWT signature?
No. Decoding only reveals the token contents; signature verification is a separate step.
Is a JWT encrypted?
No. A JWT is usually encoded, not encrypted, so the payload is readable to anyone who has the token.
Should I paste sensitive tokens into a browser tool?
Only if you trust the page and understand the token is being inspected locally. Sensitive tokens should never be shared with untrusted services.
Related tools
Encode text to Base64 or decode it back when you need to inspect API payloads, URLs, or encoded data quickly.
Format JSON instantly in your browser. Paste a payload, tidy the structure, and copy or download the result without affecting the data itself.
Validate JSON in seconds and catch syntax issues before your application fails on a malformed payload.