100% browser-based

JWT Decoder

Paste a JWT to read what is inside it. The token stays in this browser while Opselith decodes it.

How to use this →

LOCAL PROCESSINGNO UPLOADFREE
TOKEN TOOL

Read a JSON Web Token (JWT)

See the information stored in the token. This does not prove that the token is valid or trusted.

READY
01PASTEAdd the token
02DECODERead its contents
03REVIEWCheck the details
01 / INPUT

Paste the JWT

Paste the full token. A JWT normally has three sections separated by dots.

LOCAL ONLY
Reading the token does not check whether its signature is valid.
Stays in this browserOpselith does not upload the token while you decode it.

Inspect JWT claims without uploading the token

Use this to inspect the header, issuer, audience and expiry in a JSON Web Token. It decodes the token but does not verify its cryptographic signature.

Important security limitation

A decoded JWT is not automatically trustworthy. Signature verification and issuer, audience and policy validation must still happen in the system that consumes the token.

CONTINUE

Keep working in Opselith.

Open another tool or switch to the PowerShell Builder.