JWT Decoder

My tools
No tools yet

Loading...

Decode and verify a JWT online

  1. 1

    Paste the JWT

    Paste the three-part token (header.payload.signature) into the input box; the header and payload are decoded and formatted as JSON instantly. You can also load a sample token.

  2. 2

    Read the claims and time fields

    The exp, iat, and nbf claims are converted to local time and ISO 8601 automatically, with an expiry badge on exp so you can check the token status at a glance.

  3. 3

    Verify the signature with your secret

    Enter the signing secret and the tool verifies the HS256 signature locally and shows the result, with clear messages for mismatched signatures or unsupported algorithms.

Features Overview

Online JWT decoder: paste a token to instantly decode its header, payload, and signature, verify the HS256 signature locally with your secret, and read exp/iat/nbf claims as human-friendly times with expiry status. Everything runs in your browser.

Tool Description

Decode JWT tokens online: three-section decoding, HS256 verification, and human-friendly time claims, all processed locally in your browser.

Last updated

Capabilities Checklist

  • Instant decoding: splits and formats the JWT header, payload, and signature sections
  • HS256 signature verification: computes HMAC-SHA256 locally and compares against the signature; your secret never leaves the browser
  • Human-friendly time claims: exp, iat, and nbf are shown in local time and ISO 8601, with expiry status for exp
  • Privacy first: decoding and verification run entirely client-side with no network requests

User feedback

Your feedback will be reviewed (and redacted if needed) before it appears publicly. Please do not include emails, passwords, or other personal information.

Your feedback helps us do better ❤️

Related Tools

Related Guides

Frequently Asked Questions

Does this tool support verifying JWT signatures?
Yes. Enter the signing secret and the tool computes HMAC-SHA256 over header.payload locally and compares it with the signature section, showing immediately whether it matches. Nothing is sent over the network. HS256 is supported today; RS256 and other asymmetric algorithms are planned for a later release.
Does a successfully decoded token mean the token is valid?
No. Decoding only reads the Base64URL-encoded claims, which anyone can do and which cannot prove the content was not tampered with. Only a verified signature confirms the token was issued by someone holding the secret, and whether it is still within its validity period also depends on the exp claim and the expiry status shown.
Does verification send my token or secret to a server?
No. Both decoding and HS256 verification happen inside this page with no network requests. As a general habit, prefer test tokens over production tokens with live sessions when using any online tool.