JWT decoder
Decode a JSON Web Token and verify its signature.
Try
waiting for a token…
About this tool
- Runs in
- your browser
- Your input sent to our servers
- Nothing
- Kept on this device
- nothing
More in the privacy policy.
How to use it
- 01Paste a JWT (with or without “Bearer ”), or pick one under Try; the examples come with their keys.
- 02Read the status (expired, not yet valid, or not expired, judged by the clock only) and any warnings, then the header, the payload and the claims with their times in UTC and your time zone.
- 03To check the signature, enter the secret (HS256, HS384, HS512; tick Secret is Base64 if it’s encoded) or paste the public key as a PEM or JWK (RS, PS and ES algorithms, and EdDSA). The verdict shows under the status.
- 04Copy the header or payload JSON. A signature checked here helps you debug; your server should still verify every token with its own JWT library.
Related tools
Questions
Can it check the signature?
Yes, with the key: decoding needs none, verifying does. Enter the secret for HS256, HS384 or HS512, or paste the public key for RS256–512, PS256–512, ES256–512 or EdDSA (Ed25519, in browsers that support it) as a PEM (BEGIN PUBLIC KEY), a JWK or a JWK set (the key with the token’s kid is used). “Signature verified” means the token was signed with the matching key and hasn’t changed since; it doesn’t make the claims true, so still check exp, iss and aud.
Is it safe to paste a token or key here?
The token and the key are used in this tab, with your browser's Web Crypto. They aren't sent to our servers, and they aren't kept after you leave the page. Still treat a live token like a password: anyone who has it can use it until it expires. A public key is safe to share; for HS tokens, prefer a test secret over a production one.
What do exp, iat and nbf mean?
They are times in seconds since 1970-01-01 UTC: exp is when the token expires, iat when it was issued, nbf the earliest time it may be used. The expired example's exp, 1700003600, is 2023-11-14T23:13:20Z.
Why can I read the payload?
A signed JWT is only Base64url-encoded, not encrypted: anyone can read it, and the signature only proves it wasn’t changed. Encrypted tokens (JWE, five parts) keep the payload secret.