WhatsOnTool directory

JWT Decoder, Unverified

Read JWT header and payload without verifying the signature or trusting claims.

Open this tool

A decoded token reveals its header and claims, but those values may have been altered.

Read the payload for inspection while keeping authentication decisions outside the decoder.

Inputs and controls

Three part JWT

Example token

Use a sample token. This input is sent to the WordPress server.

How to use

Why use this tool

The unverified presentation separates readable content from trusted identity.

Before relying on the result

UNVERIFIED. Decoding does not establish authenticity, expiry validity or permission. Encrypted five part tokens are not supported.

Tool limitations

UNVERIFIED. Decoding does not establish authenticity, expiry validity or permission. Encrypted five part tokens are not supported.

Questions

Does decoding validate the signature or expiry?

No. Neither authenticity nor expiry validity is established by reading the claims.

What should I check before using JWT Decoder, Unverified?

Check Three part JWT. Use the exact units shown beside the controls and replace any example values with your own inputs.

Source page last modified: 2026-10-04T16:58:30+00:00. This profile describes the tool; use its page to run it.

Markdown profile