What the decoder shows
- The header (algorithm and token type) and payload (claims) as formatted JSON.
- Readable dates for
iat(issued at),nbf(not before) andexp(expires), and whether the token has expired. - Standard claims: issuer, subject, audience and token ID.
Verifying the signature
Enter the secret for HS256/HS384/HS512, or the public key in PEM format for RS, PS and ES algorithms. Verification uses your browser's Web Crypto API. A valid signature proves the token was issued by the key holder and not modified.
Security notes
- A JWT payload is only encoded, not encrypted — anyone can read it. Never put passwords in it.
- Reject tokens with
alg: none. - Everything runs in your browser; tokens and keys are never sent anywhere.
Frequently asked questions
Is it safe to paste my token here?
Yes. Decoding and verification run locally in your browser and nothing is uploaded. Still, avoid sharing live production tokens.
Why does verification fail?
The secret or key does not match, the token was modified, or the public key is not in PEM (BEGIN PUBLIC KEY) format.
Can it decrypt JWE tokens?
No. JWE tokens are encrypted (five parts); this tool decodes signed JWS tokens.

