JWT Decoder: What's Inside Your JSON Web Token (And Why Pasting It Online Is a Security Breach)
Learn how to decode a JWT token, understand its three parts, and why using a cloud-based decoder exposes your active session to third-party servers. Decode locally in your browser.
A JWT has three Base64URL-encoded parts — header, payload, and signature. The header and payload are fully readable without any key, meaning any cloud decoder that receives your token also receives your active session credential and any PII embedded in the claims.