JWT Decoder & Debugger
Paste a JWT to see its header and claims, when it was issued and when it expires. Add the secret or public key to verify the signature. Tokens are never sent anywhere, which matters because a JWT is a credential.
How it works
A JWT (RFC 7519) is three Base64URL strings joined by dots: header, payload, signature. The first two are just encoded JSON, so anyone holding the token can read them. Never put secrets in a payload.
The signature is computed over "header.payload" with the algorithm named in the header. Verification recomputes it with your key using the browser’s Web Crypto API.
exp, nbf and iat are NumericDate values: seconds since 1970-01-01 UTC. They are shown in your local time and relative to now.
Everything above runs in JavaScript inside this tab. Your data is not uploaded. Inputs are remembered in this browser only so they survive a reload; you can switch that off on the privacy page.
Questions
Is it safe to paste a production token here?
Decoding and verification run entirely in your browser; the token is not uploaded or stored. Still, treat live tokens as passwords and prefer expired or test tokens when you can.
Does decoding a JWT mean it is valid?
No. Anyone can decode a JWT. It is only trustworthy after the signature is verified with the right key and exp, nbf, iss and aud are checked.
Which algorithms can be verified?
HS256/384/512 with a shared secret, RS256/384/512 and PS256/384/512 with an RSA public key (PEM or JWK), and ES256/384/512 with an EC public key.
What is "alg": "none"?
An unsigned token. Servers must reject it; accepting it was a well-known class of JWT library vulnerability.