JWT decoder
Paste a JWT and read its header, payload, and signature instantly, with every claim explained and the expiration dates in your local time. You can also create and sign one.
The token and the key never leave your browser: they are not sent, not stored, and do not end up in the page address.
Paste a token to see its header, payload, and signature instantly, with every claim explained.
This is not a valid JWT
Token by parts
Header
Payload
The payload carries the data of the token. It is encoded, not encrypted: anyone with the token can read it.
Claims explained
Signature
Verify the signature (optional)
Used as is, as text. It is checked as you type.
Accepts PEM (“BEGIN PUBLIC KEY”), an X.509 certificate, a JWK, or a JWKS set. Never paste a private key.
Is it safe to paste a token here?
This page decodes the token with JavaScript in your browser: there is no server that receives it. You can check this by opening the Network tab of your browser developer tools while you paste the token.
Even so, do not paste live production tokens on sites you cannot audit. A stolen token works like a password until it expires. If in doubt, use a test token or one that has already expired.
Use test secrets and keys only. What you type here does not leave your browser, is not stored, and does not end up in the page address, but you should not paste production keys anywhere.
“iat” is when it was issued and “exp” is when it expires, in seconds since 1970.
Used as is, as text. It should be at least as many bytes as the hash (32 for HS256).
Accepts a PEM without a password (“BEGIN PRIVATE KEY” or “BEGIN RSA PRIVATE KEY”) or a JWK with “d”. Signing happens in your browser.
Signed token
Public key to verify it
How to use it
- Paste the token into the field. We accept “Bearer eyJ…”, an Authorization header, or JSON that contains it: we find the JWT inside it.
- Look at the decoded header and payload, with tidy JSON and a table that explains every claim in plain English.
- Check the status: we tell you whether the token is valid, expired, or not valid yet, with the date in your local time and in UTC.
- To check the signature, type the secret key (HS256) or paste the public key as PEM, JWK, or a certificate (RS256, ES256, PS256, EdDSA).
- To create a token, switch to “Create token”: write the header and payload, choose the algorithm, enter the key, and copy the result or select “Decode this token”.
Frequently asked questions
Is it safe to paste my token here?
The token is decoded in your browser with JavaScript and is not sent to any server: you can confirm this in the Network tab of your developer tools. We also do not store it or put it in the page address. Still, be careful with production tokens that are still valid: a stolen token works like a password until it expires.
What does it mean when the signature is valid?
It means the token was not modified after it was signed and that the key you typed is the one that signed it. It does not prove that the issuer is trustworthy, that the token is still valid (check “exp”), or that it is meant for your service (check “aud”). Your server must check all of that.
Why can I read the contents of a JWT without any key?
Because the header and the payload are only encoded in Base64URL, not encrypted. The signature detects changes; it does not hide data. That is why you should never store passwords or sensitive data inside a JWT. Encrypted tokens (JWE) have five parts and do need a key to be read.
What is “alg: none” and why is it flagged?
It is a token that declares itself unsigned. Anyone can write one with whatever content they want, so a server must never accept it as proof of identity. Some old libraries accepted it by mistake, which is a classic attack. If you see “none” in a real token, be suspicious.
Which keys can I use to verify the signature?
For HS256, HS384, and HS512, the secret key as text (or in Base64 if you turn that option on). For RS, PS, ES, and EdDSA, the public key as PEM (“BEGIN PUBLIC KEY”), an X.509 certificate, a JWK, or a JWKS set (we pick the key by its “kid”). To create a token you need the private key as an unencrypted PEM or a JWK with “d”; you can also generate a test pair.
Why does my token show as expired if it was just issued?
The “exp” field is a number of seconds since 1970. If the issuer wrote it in milliseconds, or your device clock is off, the status comes out wrong. We warn you when a value looks like milliseconds or when “iat” is in the future.
What a JWT is
A JSON Web Token is three parts separated by dots: header.payload.signature. The first two are JSON encoded in Base64URL; the third is the signature that stops them from being changed without anyone noticing. JWTs are used for signing in and for authorizing API calls.
The most common claims
iss: who issued the token.sub: who it is about, usually a user ID.aud: which service it is for.exp: when it expires, in seconds since 1970.nbf: the time before which it is not valid.iat: when it was issued.jti: a unique identifier for the token.
Decoding is not verifying
Anyone can read a JWT. What matters is that your server checks the signature with its own key, chooses the expected algorithm itself (never the one the token claims), and checks exp, nbf, iss, and aud before trusting the content.
Signing algorithms
HS256 uses a shared secret key. RS256 and PS256 use an RSA key pair, and ES256 uses an elliptic curve: you sign with the private key and verify with the public key, which can be published safely. If the payload is JSON you want to inspect, try the JSON formatter.
Updated on September 29, 2026