JWT Decoder
Read the header and claims inside any JWT, check expiry and verify HMAC signatures.
How to use: Paste a token (with or without “Bearer”) to see its header, payload and expiry. To check an HS256 signature, enter the secret and press Verify.
Verify signature (HMAC)
How to use the JWT Decoder
JSON Web Tokens are used by many login systems and APIs to carry identity and permissions. A JWT has three parts separated by dots: a header that names the signing algorithm, a payload of claims such as the user ID and expiry time, and a signature. The first two parts are only Base64URL-encoded, not encrypted, so anyone holding the token can read them.
Paste a token and the decoder shows the header and payload as formatted JSON, plus a table of every claim. Standard claims are labelled: iss is the issuer, sub the subject, aud the audience, iat the time it was issued, nbf the time it becomes valid and exp the expiry. Times are converted from Unix seconds to readable dates in your time zone, and the status tells you whether the token is still valid and for how long.
To check that a token was signed with a particular shared secret, type the secret and press Verify. HS256, HS384 and HS512 are supported using your browser’s built-in Web Crypto. Tokens signed with RS256 or ES256 need a public key and are not verified here.
Decoding happens locally, so tokens are not sent anywhere. Still, treat real tokens like passwords and avoid pasting production secrets on shared computers.
Frequently asked questions
Is a JWT encrypted?
Usually not. Standard signed tokens are only encoded, so never put secrets such as passwords in the payload.
Is it safe to paste my token here?
The token is decoded in your browser and never sent to a server. Still avoid sharing live tokens with anyone.
Why does verification fail?
The secret is different, the token was changed, or it uses an algorithm such as RS256 that needs a public key.