JWT Decoder
Paste a JWT to read what is inside it. The token stays in this browser while Opselith decodes it.
Read a JSON Web Token (JWT)
See the information stored in the token. This does not prove that the token is valid or trusted.
Paste the JWT
Paste the full token. A JWT normally has three sections separated by dots.
Token header
Technical information about how the token was created.
Token details (claims)
The information the token carries, such as IDs, roles or dates.
Quick checks
These checks help you spot missing fields. They do not prove the token is valid.
Inspect JWT claims without uploading the token
Use this to inspect the header, issuer, audience and expiry in a JSON Web Token. It decodes the token but does not verify its cryptographic signature.
Important security limitation
A decoded JWT is not automatically trustworthy. Signature verification and issuer, audience and policy validation must still happen in the system that consumes the token.
Keep working in Opselith.
Open another tool or switch to the PowerShell Builder.