JWT Decoder & Verifier

Decode JSON Web Tokens, check expiry and verify HS, RS, PS and ES signatures — all in your browser.

What is a JWT?

A JSON Web Token (JWT) is a compact, signed token made of three Base64URL parts — header, payload and signature — used to pass identity and permissions between a client and a server.

What the decoder shows

  • The header (algorithm and token type) and payload (claims) as formatted JSON.
  • Readable dates for iat (issued at), nbf (not before) and exp (expires), and whether the token has expired.
  • Standard claims: issuer, subject, audience and token ID.

Verifying the signature

Enter the secret for HS256/HS384/HS512, or the public key in PEM format for RS, PS and ES algorithms. Verification uses your browser's Web Crypto API. A valid signature proves the token was issued by the key holder and not modified.

Security notes

  • A JWT payload is only encoded, not encrypted — anyone can read it. Never put passwords in it.
  • Reject tokens with alg: none.
  • Everything runs in your browser; tokens and keys are never sent anywhere.

Frequently asked questions

Is it safe to paste my token here?

Yes. Decoding and verification run locally in your browser and nothing is uploaded. Still, avoid sharing live production tokens.

Why does verification fail?

The secret or key does not match, the token was modified, or the public key is not in PEM (BEGIN PUBLIC KEY) format.

Can it decrypt JWE tokens?

No. JWE tokens are encrypted (five parts); this tool decodes signed JWS tokens.