JWTEncoding & Decoding

JWT Decoder

Decode JWT headers and payloads locally without exposing secrets.

Runs entirely in your browser. Your data never leaves your device.

Decode JWT tokens locally to inspect the header and payload without sending a token to a remote service.

What is this tool?

A JWT is a compact token format commonly used to carry identity and authorization data between systems. It consists of three parts: a header, a payload, and a signature. The header and payload are base64url-encoded, so they can be decoded and inspected by developers when debugging authentication flows or reviewing claims. Decoding a JWT does not verify the signature; it only reveals the token contents.

Example

Example token

Common JWT structure

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwidXNlcm5hbWUiOiJjYXNzaWRvciJ9.signature

Header

Token metadata

{
  "alg": "HS256",
  "typ": "JWT"
}

Why use Cassidor?

  • Helps inspect token claims directly in the browser.
  • Useful for debugging authentication and authorization issues.
  • Keeps token inspection local and transparent.

Frequently asked questions

What information can I see in a JWT?

You can inspect the decoded header and payload, which often include algorithms, claim names, and user or session metadata.

Does decoding verify a JWT signature?

No. Decoding only reveals the token contents; signature verification is a separate step.

Is a JWT encrypted?

No. A JWT is usually encoded, not encrypted, so the payload is readable to anyone who has the token.

Should I paste sensitive tokens into a browser tool?

Only if you trust the page and understand the token is being inspected locally. Sensitive tokens should never be shared with untrusted services.

Related tools