Developer
JWT decoder
Read a JWT locally, or mint an unsigned fixture. This is not signature validation.
This tool processes files and text locally in your browser. Your content is not uploaded or stored by this site.
Loading the workbench…
What this tool does
Decode mode splits a compact JWS into three Base64URL segments, reads the first two as JSON, and tells you whether a signature segment is present. Build unsigned writes header {"alg":"none","typ":"JWT"} and an empty signature. It never contacts an identity provider, never verifies HMAC or RSA, and never signs.
How to use it
- Choose Decode or Build unsigned.
- Paste a token, or paste payload JSON for a fixture.
- Read the warning. Treat every claim as untrusted text. An unsigned token is not authentication.
- Inspect header.alg, exp, and your application claims, or copy the fixture.
Supported input
- A compact JWS token, or payload JSON, up to 32 KB
Output
- Decoded JSON with header, payload, signaturePresent, and alg — or an alg none compact token
Privacy
This tool processes files and text locally in your browser. Your content is not uploaded or stored by this site.
ConvertPass does not include your input in analytics, URLs, or error reports. Encoding: UTF-8 JSON inside Base64URL. Limit: 32 KB (32.0 KB).
Limitations
- No signature verification, ever, in this tool.
- Build unsigned always uses alg none and an empty signature. It will not accept a secret or private key.
- Encrypted JWTs (JWE) are not decrypted.
- alg none is displayed, not treated as valid.
Example
eyJhbGciOiJub25lIn0.eyJzdWIiOiJhZGEiLCJpc3MiOiJjb252ZXJ0cGFzcyIsImV4cCI6MTcwMDAwMDAwMH0.
{
"header": { "alg": "none" },
"payload": { "sub": "ada", "iss": "convertpass", "exp": 1700000000 },
"signaturePresent": false,
"algorithm": "none"
}
This example is an unsigned token for illustration.
Troubleshooting
- The header is not valid Base64URL JSON
- You may have pasted an opaque session cookie, not a JWT. JWTs contain two dots.
FAQ
Why will ConvertPass not verify the signature?
Verification needs the correct key and algorithm policy. Doing it in a random website would either require you to paste secrets, or it would pretend to verify without them. Both are worse than a clear warning.
Is it safe to paste a production token?
Treat tokens as credentials. This tool stays local, but a screenshot, browser extension, or shared machine can still leak them. Prefer a redacted token or a staging token.
What does signaturePresent mean?
Only that the third segment is non-empty. It is not a cryptographic check. An attacker can attach any bytes.
Can I create a signed token?
No. Build unsigned only writes alg none with an empty signature. That is a fixture for local tests, not authentication. ConvertPass will not take a signing key.
Does this leak the token into the URL?
No. Tokens are not written to query parameters, history, or analytics.
Related tools
- Base64 encoder and decoder
Encode or decode Base64 without uploading the payload.
- JSON formatter
Pretty-print JSON locally, or diff two documents by JSON pointer.
- UNIX timestamp converter
Translate UNIX time and ISO-8601 without a timezone guessing game.
Related guides
Related formats
Last reviewed 16 August 2026. Report a problem. Reports do not include your input.
