mtools.lol

JWT Decoder

Decode a JSON Web Token to read its header and claims, check expiry, and verify HS256 signatures.

How it works

  1. 1Paste the token (with or without Bearer).
  2. 2Read the header, claims and dates.
  3. 3Optionally enter the secret to check an HMAC signature.

Features

  • Header and payload as formatted JSON.
  • Issued, not-before and expiry dates in your time zone.
  • Expired or not, at a glance.
  • HMAC signature check without sending the secret anywhere.

Frequently asked questions

Is it safe to paste a real token?

Decoding happens in your browser and nothing is sent. Still, treat live tokens like passwords.

Can it verify RS256 tokens?

Not yet: RS/ES algorithms need the issuer's public key. HS256, HS384 and HS512 can be checked with the shared secret.

Is my data sent anywhere?

No. Everything runs in your browser; nothing is uploaded.