SECURITY
JWT Decoder & Builder
Decode JWT headers and payloads or build an unsigned token for testing.
LOCAL INSPECTION
Inspect or build JWTs
alg: none token for testing only. It is not suitable for authentication.JWT decoding and building happen in your browser and your token is never uploaded.
JWT decoder and builder guide
JSON Web Tokens (JWTs) are compact claims packaged into three dot-separated Base64url sections: a header, a payload, and a signature.
Use this page to inspect the readable parts of a token or create an unsigned token for local development tests. Decoding does not verify a signature, and JWT payloads are not encrypted.
What a JWT contains
The header normally identifies the token type and signing algorithm. The payload contains claims such as a subject, issuer, expiry time, and issued-at time. The signature lets a server detect changes when it validates the token with the correct key.
Decoding is not verification
Anyone can Base64url-decode a JWT, so never put passwords or other secrets in its payload. A trustworthy server must verify the signature, check the algorithm it expects, and validate time and audience claims before accepting the token.
Unsigned tokens
The builder creates an alg:none token for fixtures and development tests only. Production authentication tokens should use a carefully configured signing algorithm and should be validated server-side.
Frequently asked questions
Does this tool verify JWT signatures?
No. It decodes the header and payload locally. Signature verification requires the correct server key and algorithm configuration.
Are JWTs encrypted?
No. Standard signed JWTs are encoded, not encrypted. Their payload can be read by anyone who has the token.
What is an unsigned JWT?
It is a development/test token with an alg:none header and no signature. It must never be accepted for production authentication.
Privacy note: JWT decoding and building happen in your browser. Your token is not submitted to NAB Tools.