Skip to content
>_TulzaBox
Tools

JWT decoder

Decodes header and payload, checks expiry and HMAC signatures.

Everything runs in your browser: your input and files are never uploaded.

How to use

  1. Paste the whole token (the Bearer prefix is fine).
  2. Header and payload are shown as JSON, exp, iat and nbf as readable dates.
  3. For HS256/384/512 enter the secret to verify the signature.

FAQ

Is it safe to paste a token here?

The token is decoded only in your browser and never sent anywhere. Still, do not paste production tokens into sites you do not trust.

Is a JWT encrypted?

No. The header and payload are plain Base64 anyone can read. The signature prevents tampering but does not hide data.

Which signatures can be verified?

HMAC: HS256, HS384, HS512 with a shared secret. RS256 and ES256 need a public key and are not supported yet.

Related tools