JWT decoder
Decodes header and payload, checks expiry and HMAC signatures.
Everything runs in your browser: your input and files are never uploaded.
How to use
- Paste the whole token (the Bearer prefix is fine).
- Header and payload are shown as JSON, exp, iat and nbf as readable dates.
- For HS256/384/512 enter the secret to verify the signature.
FAQ
Is it safe to paste a token here?
The token is decoded only in your browser and never sent anywhere. Still, do not paste production tokens into sites you do not trust.
Is a JWT encrypted?
No. The header and payload are plain Base64 anyone can read. The signature prevents tampering but does not hide data.
Which signatures can be verified?
HMAC: HS256, HS384, HS512 with a shared secret. RS256 and ES256 need a public key and are not supported yet.