Small ToolsAll tools
← All tools / Security
Security utility

JWT Header Decoder

Decode the protected header segment of a JWT locally.

● This tool runs entirely in your browser. Your input is never uploaded to our servers.

Decoding does not verify the signature. Treat all claims as untrusted.

Output
Your result will appear here…

How to use JWT Header Decoder

  1. Paste a JWT or its three-segment compact representation.
  2. Select Decode Header to inspect the first segment.
  3. Remember that header values are untrusted until signature validation.

Example

Input:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTEyMyJ9.signature

Output:

{
  "alg": "HS256",
  "typ": "JWT"
}

Use cases

About this tool

Decode the protected header segment of a JWT locally. Processing happens locally in your browser, so your input is not sent to a server or included in analytics.

Frequently asked questions

Does the alg field tell me which algorithm to trust?

No. Treat the header as untrusted input and enforce an allowed algorithm on the server.

Does header decoding check the signature?

No. It only decodes the first Base64URL segment.

Does decoding send the token anywhere?

No. It stays in your browser.

Related tools