Search tools

Search for a command to run...

JWT Decoder

Decode a JSON Web Token to read its header and payload, check expiry times, and verify HS256/384/512 signatures with your secret.

How to use

  1. 1Paste the token (three parts separated by dots).
  2. 2Read the decoded header and claims; add the secret to verify an HMAC signature.

Frequently asked questions

Is it safe to paste a JWT here?

Decoding happens entirely in your browser. Still, treat live tokens like passwords and avoid pasting production tokens into any website.

Does decoding mean the token is valid?

No. Anyone can decode a JWT. Only verifying the signature with the right key proves it wasn't forged or modified.

Why can't RS256 tokens be verified here?

RS256 and ES256 use public-key signatures. This tool verifies shared-secret (HS) tokens; public-key verification is planned.