How to use the JWT Decoder
- 1
Paste a JWT into the Encoded token box. A whole Authorization header or a quoted token from a log works too; the Bearer prefix and quotes are stripped.
- 2
Read the header and payload on the right. The Claims view explains each registered claim, resolves exp, nbf and iat to dates and relative times, and flags expired or not-yet-valid tokens. The JSON view shows the raw objects.
- 3
To verify an HS256, HS384 or HS512 signature, type the shared secret. The result updates as you type. Tick Secret is base64 if your secret is stored encoded.
- 4
Use Re-sign and copy to produce a fresh token for the same header and payload with your secret, handy for test fixtures.
- 5
Press Sample to load an example token with its secret.
Features
- Decodes header and payload instantly, with colour-coded token segments
- Claims table explaining registered claims and common OpenID Connect claims
- Resolves exp, nbf, iat and auth_time to UTC dates and relative times, and detects millisecond timestamps
- Clear verdict in the header, with expired and not-yet-valid states flagged
- Verifies HS256, HS384 and HS512 signatures with a shared secret using WebCrypto
- Explains why RS, ES, PS and none tokens cannot be verified with a secret
- Specific error messages for truncated tokens, JWE tokens, bad base64url and non-JSON parts
- Tokens stay in this browser tab for the session only; nothing is sent anywhere
What a JWT is
A JSON Web Token is three base64url strings joined by dots: a header naming the algorithm, a payload of claims about a user or session, and a signature over the first two. Because the first two parts are only encoded, not encrypted, anyone can read them, and that is by design: the signature is what makes the token trustworthy, while the claims are meant to be read by the receiving service without a database lookup.
This decoder shows the parts in colour, turns the header and payload into readable tables, and judges the token’s state at a glance: valid for another two hours, expired three days ago, or unsigned.
Verifying a signature
For tokens signed with a shared secret (HS256 and its siblings), type the secret and the tool computes the HMAC with the browser’s WebCrypto API and compares it to the signature. A green badge means the token is authentic and unmodified; a red one means the secret is wrong or the token was altered. Public-key algorithms such as RS256 need the issuer’s public key, which this tool does not fetch; the token is still fully decoded and explained.
Re-sign and copy takes the decoded header and payload, signs them with the secret you typed and copies the result. Edit the claims in the JSON view by copying them to the JSON Editor, then paste a token back here to sign it when you need test fixtures.
Related tasks
The signature and the two JSON parts are plain base64url, which the Base64 Encoder handles. To convert NumericDate claims by hand, use the Timestamp Converter.
Frequently asked questions
Is it safe to paste a real token here?
Why can I decode a JWT without the secret?
Which algorithms can be verified here?
What do exp, nbf and iat mean?
Why does the tool say my token has five segments?
What does Secret is base64 do?
Last updated .