Decode and inspect JWT token headers and payloads instantly.
About this tool
JSON Web Tokens (JWTs) are base64url-encoded JSON objects separated by dots. This tool decodes the header and payload sections so you can inspect claims, expiry, and algorithm without verifying the signature. Never paste production tokens into online tools — this tool runs entirely in your browser.
Runs in your browser — nothing is uploaded; your input never leaves your device. How it works
Quick answer
Paste a JWT and Tabreon instantly decodes its header and payload — plus issued-at, expiry, and whether it's expired — entirely in your browser, without verifying or transmitting the signature.
Why use Tabreon for this?
Decoding happens entirely client-side — a JWT often carries session or identity claims, and it's never sent to a server here.
Shows a plain-language summary (issued at, expires at, expired yes/no, algorithm) alongside the raw decoded JSON.
No account, no limit on how many tokens you can inspect.
How to decode a JWT
1Paste the token. Paste a JWT (three base64url segments separated by dots) into the input box.
2Read the header and payload. The decoded header and payload JSON appear instantly.
3Check the token info. The Token Info panel shows issued-at time, expiry time, whether it's expired, and the signing algorithm.
What is a JWT?
A JWT (JSON Web Token) is a compact, URL-safe token made of three base64url-encoded segments — a header, a payload, and a signature — separated by dots. The header and payload are plain JSON once decoded (not encrypted, just encoded), which is why anyone can read a JWT's claims without the secret key. Only the signature, which this tool does not verify, actually proves the token wasn't tampered with.
How Tabreon handles your data
Decoding runs entirely in your browser by base64url-decoding the token's header and payload — a JWT often carries session or identity claims, and it is never sent to a server here. Still, treat any real token as sensitive: decoding it doesn't require the signing key, so anyone who has the token can read its claims.
Key features
Decodes both header and payload sections independently
Token Info summary: issued-at, expiry, expired status, and algorithm
Handles the base64url encoding JWTs use (different padding from standard Base64)
Clear error if the input isn't a valid 3-part JWT
Common use cases
Inspecting what claims an access token actually carries during API debugging
Checking whether a token has expired without decoding it by hand
Confirming which signing algorithm (e.g. HS256, RS256) a token uses
Common mistakes & limitations
This tool decodes and displays claims only — it does not verify the signature, so it cannot confirm the token is authentic or hasn't been tampered with.
Avoid pasting real production tokens into any online tool, including this one, on a shared or untrusted machine — decoding is local, but the token itself grants access to whatever it authenticates.
Frequently asked questions
No. This tool decodes the header and payload so you can read the claims, but it does not check the signature against a secret or public key — it cannot tell you whether the token is genuinely valid.
No, decoding happens entirely in your browser.
A JWT must have exactly three parts separated by dots (header.payload.signature). If your input is missing a section or has extra dots, decoding fails with this message.