100% in your browser
Your tools. Your flow.

See what your token says.

Inspect a JSON Web Token’s header, claims and timestamps.

Source
Output
Paste some text to get started
—Processed locally

Decoding only. The signature is not verified, so this does not prove the token is authentic.

Decode a JSON Web Token privately

Paste a JWT with three dot-separated segments. Devkit decodes the Base64URL header and payload segments and presents their contents as JSON. The iat, nbf and exp time claims are also shown as ISO dates. Your token remains in your browser’s memory.

Does decoding verify the JWT signature?

No. A forged token can have a perfectly readable header and payload. This tool does not establish authenticity or whether an API should accept the token.

Can I inspect an encrypted JWE token?

No. This tool expects the three-segment structure of a signed JWT. It does not decrypt JWE tokens.

No account. No uploads. Just the essentials.Privacy · Licenses