JWT Decoder
Decode a JSON Web Token to read its header and claims, check expiry, and verify HS256 signatures.
How it works
- 1Paste the token (with or without Bearer).
- 2Read the header, claims and dates.
- 3Optionally enter the secret to check an HMAC signature.
Features
- Header and payload as formatted JSON.
- Issued, not-before and expiry dates in your time zone.
- Expired or not, at a glance.
- HMAC signature check without sending the secret anywhere.
Frequently asked questions
Is it safe to paste a real token?
Decoding happens in your browser and nothing is sent. Still, treat live tokens like passwords.
Can it verify RS256 tokens?
Not yet: RS/ES algorithms need the issuer's public key. HS256, HS384 and HS512 can be checked with the shared secret.
Is my data sent anywhere?
No. Everything runs in your browser; nothing is uploaded.
Related tools
Base64 DecoderDecode Base64 (standard or URL-safe) back to text.Hash GeneratorGet MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or a file, with optional HMAC.JSON Formatter & ValidatorFormat, validate and minify JSON with clear error messages.Base64 EncoderEncode text to Base64, with a URL-safe option.