Skip to content
ConvertPass home

Developer

JWT decoder

Read a JWT locally, or mint an unsigned fixture. This is not signature validation.

This tool processes files and text locally in your browser. Your content is not uploaded or stored by this site.

Loading the workbench…

What this tool does

Decode mode splits a compact JWS into three Base64URL segments, reads the first two as JSON, and tells you whether a signature segment is present. Build unsigned writes header {"alg":"none","typ":"JWT"} and an empty signature. It never contacts an identity provider, never verifies HMAC or RSA, and never signs.

How to use it

  1. Choose Decode or Build unsigned.
  2. Paste a token, or paste payload JSON for a fixture.
  3. Read the warning. Treat every claim as untrusted text. An unsigned token is not authentication.
  4. Inspect header.alg, exp, and your application claims, or copy the fixture.

Supported input

  • A compact JWS token, or payload JSON, up to 32 KB

Output

  • Decoded JSON with header, payload, signaturePresent, and alg — or an alg none compact token

Privacy

This tool processes files and text locally in your browser. Your content is not uploaded or stored by this site.

ConvertPass does not include your input in analytics, URLs, or error reports. Encoding: UTF-8 JSON inside Base64URL. Limit: 32 KB (32.0 KB).

Limitations

  • No signature verification, ever, in this tool.
  • Build unsigned always uses alg none and an empty signature. It will not accept a secret or private key.
  • Encrypted JWTs (JWE) are not decrypted.
  • alg none is displayed, not treated as valid.

Example

Input
eyJhbGciOiJub25lIn0.eyJzdWIiOiJhZGEiLCJpc3MiOiJjb252ZXJ0cGFzcyIsImV4cCI6MTcwMDAwMDAwMH0.
Output
{
  "header": { "alg": "none" },
  "payload": { "sub": "ada", "iss": "convertpass", "exp": 1700000000 },
  "signaturePresent": false,
  "algorithm": "none"
}

This example is an unsigned token for illustration.

Troubleshooting

The header is not valid Base64URL JSON
You may have pasted an opaque session cookie, not a JWT. JWTs contain two dots.

FAQ

Why will ConvertPass not verify the signature?

Verification needs the correct key and algorithm policy. Doing it in a random website would either require you to paste secrets, or it would pretend to verify without them. Both are worse than a clear warning.

Is it safe to paste a production token?

Treat tokens as credentials. This tool stays local, but a screenshot, browser extension, or shared machine can still leak them. Prefer a redacted token or a staging token.

What does signaturePresent mean?

Only that the third segment is non-empty. It is not a cryptographic check. An attacker can attach any bytes.

Can I create a signed token?

No. Build unsigned only writes alg none with an empty signature. That is a fixture for local tests, not authentication. ConvertPass will not take a signing key.

Does this leak the token into the URL?

No. Tokens are not written to query parameters, history, or analytics.

Related tools

Related guides

Related formats

Last reviewed 16 August 2026. Report a problem. Reports do not include your input.