Paste a token, payload or encoded string. Peel works out what it is, unwraps it and keeps going, showing every layer so you can see how it was built. It recognises URL-encoding, Base64 and Base64url, hex, \uXXXX escapes, JSON Web Tokens, Unix timestamps and JSON.
What you get
JWT: header and payload decoded and pretty-printed, with iat and exp shown as readable dates and a clear expired or still valid note. The signature is not verified.
JSON: pretty-printed with a value count, or, if it is broken, the exact line and column of the error.
Timestamps: 10-digit (seconds) and 13-digit (milliseconds) Unix times shown as UTC dates.
Wrap it back up: encode the result as Base64, URL-encoding or hex, minify JSON, or compute SHA-256 and SHA-1 hashes.
Questions
Is it safe to paste a token here?
Decoding runs locally in your browser and nothing is sent to a server. Still, treat live secrets with care: a JWT is only encoded, not encrypted, so anyone holding it can read its payload.
Does Peel verify JWT signatures?
No. It only reads the contents. Verifying a signature needs the secret or public key.
What is Base64url?
A variant of Base64 that uses - and _ instead of + and / and usually drops the = padding. JWTs use it.
Base64, URL ve JWT çözücü
Bir token ya da kodlanmış metin yapıştır; Peel ne olduğunu bulur, katman katman açar ve her adımı gösterir. Base64, URL kodlaması, hex, unicode kaçışları, JWT, Unix zaman damgası ve JSON desteklenir. Her şey tarayıcında çalışır, hiçbir şey sunucuya gönderilmez.