Security utility
JWT Header Decoder
Decode the protected header segment of a JWT locally.
● This tool runs entirely in your browser. Your input is never uploaded to our servers.
Output
Your result will appear here…
How to use JWT Header Decoder
- Paste a JWT or its three-segment compact representation.
- Select Decode Header to inspect the first segment.
- Remember that header values are untrusted until signature validation.
Example
Input:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTEyMyJ9.signature
Output:
{
"alg": "HS256",
"typ": "JWT"
}Use cases
- Inspect declared JWT algorithms.
- Review key identifiers and token types.
- Debug JWT creation during development.
About this tool
Decode the protected header segment of a JWT locally. Processing happens locally in your browser, so your input is not sent to a server or included in analytics.
Frequently asked questions
Does the alg field tell me which algorithm to trust?
No. Treat the header as untrusted input and enforce an allowed algorithm on the server.
Does header decoding check the signature?
No. It only decodes the first Base64URL segment.
Does decoding send the token anywhere?
No. It stays in your browser.