Skip to content
Cuisdev

JWT Decoder

Inspect JWT header, payload and expiry without a server

  • Runs in your browser
  • No sign-up
  • Free forever
Loading the tool…

How to use the JWT Decoder

  1. 1

    Paste a JWT into the Encoded token box. A whole Authorization header or a quoted token from a log works too; the Bearer prefix and quotes are stripped.

  2. 2

    Read the header and payload on the right. The Claims view explains each registered claim, resolves exp, nbf and iat to dates and relative times, and flags expired or not-yet-valid tokens. The JSON view shows the raw objects.

  3. 3

    To verify an HS256, HS384 or HS512 signature, type the shared secret. The result updates as you type. Tick Secret is base64 if your secret is stored encoded.

  4. 4

    Use Re-sign and copy to produce a fresh token for the same header and payload with your secret, handy for test fixtures.

  5. 5

    Press Sample to load an example token with its secret.

Features

  • Decodes header and payload instantly, with colour-coded token segments
  • Claims table explaining registered claims and common OpenID Connect claims
  • Resolves exp, nbf, iat and auth_time to UTC dates and relative times, and detects millisecond timestamps
  • Clear verdict in the header, with expired and not-yet-valid states flagged
  • Verifies HS256, HS384 and HS512 signatures with a shared secret using WebCrypto
  • Explains why RS, ES, PS and none tokens cannot be verified with a secret
  • Specific error messages for truncated tokens, JWE tokens, bad base64url and non-JSON parts
  • Tokens stay in this browser tab for the session only; nothing is sent anywhere

What a JWT is

A JSON Web Token is three base64url strings joined by dots: a header naming the algorithm, a payload of claims about a user or session, and a signature over the first two. Because the first two parts are only encoded, not encrypted, anyone can read them, and that is by design: the signature is what makes the token trustworthy, while the claims are meant to be read by the receiving service without a database lookup.

This decoder shows the parts in colour, turns the header and payload into readable tables, and judges the token’s state at a glance: valid for another two hours, expired three days ago, or unsigned.

Verifying a signature

For tokens signed with a shared secret (HS256 and its siblings), type the secret and the tool computes the HMAC with the browser’s WebCrypto API and compares it to the signature. A green badge means the token is authentic and unmodified; a red one means the secret is wrong or the token was altered. Public-key algorithms such as RS256 need the issuer’s public key, which this tool does not fetch; the token is still fully decoded and explained.

Re-sign and copy takes the decoded header and payload, signs them with the secret you typed and copies the result. Edit the claims in the JSON view by copying them to the JSON Editor, then paste a token back here to sign it when you need test fixtures.

The signature and the two JSON parts are plain base64url, which the Base64 Encoder handles. To convert NumericDate claims by hand, use the Timestamp Converter.

Frequently asked questions

Is it safe to paste a real token here?
Yes. Decoding and verification run in your browser with JavaScript and the WebCrypto API; the token is never sent to a server and is kept only in this tab's session storage so it disappears when you close the tab. Even so, treat production tokens as credentials: do not paste them into tools you do not trust, and rotate them if they leak.
Why can I decode a JWT without the secret?
A JWT is signed, not encrypted. The header and payload are base64url-encoded JSON that anyone can read. The signature only proves that the token was issued by someone holding the key and has not been altered. Never put secrets in a JWT payload.
Which algorithms can be verified here?
HS256, HS384 and HS512, which use a shared secret with HMAC. Tokens signed with RS256, ES256, PS256 and the other public-key algorithms need the issuer's public key, usually published at a JWKS URL, so they are decoded and inspected but not verified. Tokens with alg none are unsigned and should be rejected by servers.
What do exp, nbf and iat mean?
They are NumericDate claims, seconds since 1 January 1970 UTC. exp is the expiry after which the token must be rejected, nbf is the moment before which it must not be accepted, and iat is when it was issued. The Claims view converts each to a UTC date and tells you how far in the past or future it is.
Why does the tool say my token has five segments?
A signed JWT (JWS) has three dot-separated parts. Five parts means an encrypted token (JWE), whose payload cannot be read without the decryption key. Two parts usually means a token with alg none missing its trailing dot, or a token truncated when copied.
What does Secret is base64 do?
Some identity providers, including older Auth0 configurations, hand out the HMAC secret base64 encoded. Tick the option to decode the secret before using it. If verification fails with the secret exactly as given to you, trying with this option on is the usual fix.

Last updated .