All Articles
Base64 & Encoding·5 min read·October 2, 2026

How to Decode JSON Web Tokens (JWT) using Base64URL

Understand the three segments of a JWT (Header, Payload, Signature) and how to decode the claims safely in the browser.

TBy Toolstack Engineering
Recommended Free Tool

Try Toolstack's Base64 URL Decoder

Free, instantaneous, and processes 100% locally in your browser.

Open Base64 URL Decoder

JSON Web Tokens (JWT) are ubiquitous in modern identity providers (Auth0, Firebase Auth, Okta) and microservices. A JWT looks like a long string separated by two dots: `aaaaaa.bbbbbb.cccccc`

The Three JWT Segments

1. Header (aaaaaa): A Base64URL-encoded JSON block identifying the signing algorithm (e.g. HS256, RS256) and token type.

2. Payload (bbbbbb): A Base64URL-encoded JSON block containing the actual data claims: subject ID (`sub`), user email, issued-at time (`iat`), expiration (`exp`), and role permissions.

3. Signature (cccccc): A cryptographic signature verifying that the header and payload have not been tampered with.

Can You Read a JWT Payload Without the Secret Key?

Yes! The cryptographic signature verifies authenticity, but the payload itself is merely Base64URL-encoded text, not encrypted. Anyone can decode and inspect the JSON claims using Toolstack's Base64URL Decoder.

Tags:#JWT#Authentication#OAuth#Security

More Guides in Base64 & Encoding