JWT Decoder
Paste a JWT to read its header and claims, check when it expires, and verify an HMAC signature. The token never leaves this tab.
Token
How to use it
- 1Paste the token; a leading "Bearer" prefix is fine.
- 2Read the header and payload; time claims are shown as dates with "expires in …".
- 3Optional: for HS256/384/512 tokens, enter the secret to check the signature.
Private by design
Everything runs in this browser tab. Your input is never uploaded, logged or saved on a server, and there are no public "recent" pages. Close the tab and it's gone.
How we keep it privateExamples
iat 1516239022 = 18 Jan 2018, 01:30:22 UTC.
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKx…
Output
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}Why decode tokens locally
A JWT is a bearer credential: whoever holds an unexpired token can call the API as that user. Pasting production tokens into a website that sends them to its server, or saves them, hands that access to someone else.
Here the token is split and Base64URL-decoded in your browser. Signature checks use the Web Crypto API, also in the browser.
Registered claims
| Claim | Meaning |
|---|---|
| iss | Issuer: who created the token |
| sub | Subject: usually the user id |
| aud | Audience: which API should accept it |
| exp | Expiry, Unix seconds: reject after this time |
| nbf | Not before, Unix seconds: reject before this time |
| iat | Issued at, Unix seconds |
| jti | Unique token id, for revocation lists |
Sources: RFC 7519 §4.1
Frequently asked questions
Does decoding a JWT prove it is valid?
No. Anyone can create a token with any payload. Only a signature check with the right key proves who issued it, and your server must also check exp, nbf, iss and aud.
Can it verify RS256 or ES256 tokens?
Not yet; signature checks currently cover HS256, HS384 and HS512 with a shared secret. Decoding works for every algorithm.
What does alg "none" mean?
The token has no signature at all. APIs must reject such tokens; accepting them is a well-known vulnerability.
Is the token or secret stored?
No. Both stay in this browser tab and are gone when you close it.