JWT Decoder
Decode and verify JSON Web Tokens
Read a JWT's header, payload and claims, check expiry, and verify HMAC, RSA or ECDSA signatures with your key.
- JWT
- JWS
- HS256
- RS256
- ES256
How to use JWT Decoder
- Paste a JWT into the token box. A leading
Bearerand line breaks are removed automatically. - Read the decoded header and payload, and the registered claims (
iss,sub,aud,exp,nbf,iat,jti) explained with dates and relative times. - Check the status badge: it says whether the token is expired or not yet valid, based on
expandnbfand your device clock. - To verify the signature, enter the shared secret (HS algorithms) or paste the public key as PEM or JWK (RS, PS and ES algorithms).
- Use Load example to try it with a sample HS256 token and its secret.
How it works
A JWT is three base64url segments separated by dots: header, payload and signature. The decoder base64url-decodes the first two, reads them as strict UTF-8 and parses them as JSON objects. The signature is decoded but not interpreted.
Verification uses the browser’s Web Crypto API (crypto.subtle.verify) over the exact header.payload text, with the algorithm named in the header’s alg: HMAC for HS256/384/512, RSASSA-PKCS1-v1_5 for RS256/384/512, RSA-PSS for PS256/384/512 and ECDSA (P-256, P-384, P-521) for ES256/384/512. Public keys are imported as SPKI PEM (BEGIN PUBLIC KEY), a JWK or a JWK Set, where the key matching the token’s kid is picked.
Limits
- Encrypted tokens (JWE, five segments) can’t be decoded; only signed tokens (JWS, three segments) are supported.
- Tokens signed with EdDSA or other algorithms outside HS, RS, PS and ES 256/384/512 can be decoded but not verified. Unsigned tokens (
"alg": "none") have nothing to verify and are flagged. - PKCS#1 RSA keys (
BEGIN RSA PUBLIC KEY), certificates and private PEM keys aren’t accepted for verification; use the SPKI public key. A private JWK works, because only its public fields are used. - Critical header extensions (
crit) are reported but not processed, and claims such asissandaudare explained, not validated against expected values. - Expiry is checked against your device clock, with no clock-skew allowance.
Privacy
Decoding and verification run entirely in your browser with built-in APIs. The token, secrets and keys are never uploaded or stored, and this tool doesn’t offer share links, so a token never ends up in a URL. If you use Send to… to open the token in another tool, it is handed over through this tab’s session storage and removed as soon as that tool reads it.
Frequently asked questions
Is it safe to paste a production token here?
The token is processed only in your browser and never sent anywhere. Still, a valid token is a credential: anyone who has it can use it until it expires, so treat it like a password wherever you paste it.
Does decoding a JWT prove it is genuine?
No. Anyone can create a token with any header and payload. Only a successful signature check with the issuer’s secret or public key shows the token was issued by them and not changed.
Why does verification fail with my RSA key?
Check that the key matches the token’s alg and is the SPKI public key (BEGIN PUBLIC KEY). A PKCS#1 key (BEGIN RSA PUBLIC KEY) can be converted with openssl rsa -RSAPublicKey_in -pubout. Certificates aren’t accepted.
My secret is Base64. How do I use it?
Turn on Secret is Base64. Standard and URL-safe Base64 are both accepted, with or without padding.
Why is the token shown as expired when the server accepts it?
Expiry is compared with your device clock without any leeway. If your clock is ahead, or the server allows clock skew, the two can disagree for tokens near their exp time.
Can it decode encrypted (JWE) tokens?
No. A JWE’s payload is encrypted, so it can’t be read without the decryption key. The tool recognises five-segment tokens and tells you so.
More tools
- Clean Image: Inspect and remove hidden image metadata
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones