Security basics

What a JWT decoder can and cannot tell you

Understand the difference between reading a token payload and verifying its authenticity.

Decoding is not verification

A JSON Web Token commonly contains a readable header and payload encoded with base64url. Anyone who has the token can often decode those parts.

The signature must be verified with the correct algorithm and key before trusting claims. A decoded payload alone does not prove who issued it or whether it has been changed.

Handle tokens carefully

Tokens can contain sensitive claims. Avoid pasting production credentials into tools you do not trust, and never share a token in logs or screenshots.

Try a related utility

Related tools