Skip to content
Sealpaste

JWT Decoder

Paste a JWT to read its header and claims, check when it expires, and verify an HMAC signature. The token never leaves this tab.

Token

How to use it

  1. 1Paste the token; a leading "Bearer" prefix is fine.
  2. 2Read the header and payload; time claims are shown as dates with "expires in …".
  3. 3Optional: for HS256/384/512 tokens, enter the secret to check the signature.

Private by design

Everything runs in this browser tab. Your input is never uploaded, logged or saved on a server, and there are no public "recent" pages. Close the tab and it's gone.

How we keep it private

Examples

Decode the payload

iat 1516239022 = 18 Jan 2018, 01:30:22 UTC.

Input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKx…

Output

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}

Why decode tokens locally

A JWT is a bearer credential: whoever holds an unexpired token can call the API as that user. Pasting production tokens into a website that sends them to its server, or saves them, hands that access to someone else.

Here the token is split and Base64URL-decoded in your browser. Signature checks use the Web Crypto API, also in the browser.

Registered claims

ClaimMeaning
issIssuer: who created the token
subSubject: usually the user id
audAudience: which API should accept it
expExpiry, Unix seconds: reject after this time
nbfNot before, Unix seconds: reject before this time
iatIssued at, Unix seconds
jtiUnique token id, for revocation lists

Sources: RFC 7519 §4.1

Frequently asked questions

Does decoding a JWT prove it is valid?

No. Anyone can create a token with any payload. Only a signature check with the right key proves who issued it, and your server must also check exp, nbf, iss and aud.

Can it verify RS256 or ES256 tokens?

Not yet; signature checks currently cover HS256, HS384 and HS512 with a shared secret. Decoding works for every algorithm.

What does alg "none" mean?

The token has no signature at all. APIs must reject such tokens; accepting them is a well-known vulnerability.

Is the token or secret stored?

No. Both stay in this browser tab and are gone when you close it.