This jwt decoder splits a token on dots, Base64URL-decodes the first segment as the header and the second as the payload, parses both as JSON, and shows the formatted JSON. It then says whether the third segment is present or empty. That is the entire job.
Verification is not performed. The page has no secret field, no password field, no HMAC, and no button that says verify. The status line says verification was not performed even when a signature segment is sitting in the token. A decoded payload is not authentic, not trusted, and not a statement that the token is unexpired. Expiry, issuer, and audience are just JSON fields if they appear. The page does not evaluate them.
The signature segment is not decoded and not printed again in the result. You can still see it in the input until you clear. Reporting its presence is enough. Decoding it would look like a check, and it is not one.
Malformed tokens stop with a reason: the wrong number of segments, a missing header or payload, a Bearer prefix, spaces inside the token, a segment that is not Base64URL, bytes that are not UTF-8, or JSON that does not parse. An unusual but parseable JSON value, such as an array, is shown and the status says it is not a JSON object. The previous header and payload are cleared whenever decode fails, so an old token cannot remain on screen under a new error.
The limit is 32,768 characters. Treat the paste as sensitive even when you are only inspecting it. The page does not write it to local storage, does not log it, and does not send it anywhere.
A normal three-segment token whose header is {"alg":"none","typ":"JWT"} and whose payload is a small object will show that JSON indented, and the status will say a signature segment is present or empty without calling the token valid. Change one character in the middle of a segment and Base64URL decode fails. Replace the payload with Base64URL of the characters not-json and JSON parse fails. Paste two segments and the structure check fails.
header.payload.signature
The segments are Base64URL, which is why the Base64 Encoder / Decoder is the related text tool. That page does not understand JWT structure, and this page will not sign or verify. If you need a general encoding of a sentence, use that tool. If you need to look at a token, stay here and read the status before you trust anything you see.
alg none in a header is displayed like any other declared algorithm. The page does not special-case it into a warning banner that implies some other alg would have been verified. None of them are verified here.
Copy is the formatted JSON. It is still sensitive if the payload contains an email, a user id, or anything else you would not post in a ticket. Clear before you leave the machine if the screen can be seen by someone else. Leaving the page also drops the values, because they live only in the document.
Do not paste a production token into a shared computer and then assume the decode result is safe to forward. The result is easier to read. It is not safer than the token.
Splits the token on dots, Base64URL-decodes the header and payload, and formats the JSON. A signature segment is only reported as present or empty. This page does not verify signatures, check expiry, or decide that the token is authentic. There is no secret field. Clear removes the token from the page. Limit: 32,768 characters.
No. There is no verify button, no secret field, and no HMAC. A present signature is only labeled as present.
No. Decode shows the JSON. It does not check the signature, expiry, issuer, or audience.
It stays in the page until you Clear or leave. It is not saved in local storage and it is not sent to a server.
JWT segments are Base64URL. The Base64 Encoder / Decoder is the general text tool. This page only splits a three-segment token.