JWT decoder
Paste a JWT: header and payload open as formatted JSON, time claims become readable, known claims are explained and weak settings are flagged. Decoding happens in your browser and the token is never sent anywhere. The tool does not verify the signature; it only optionally checks an HS256/384/512 signature with your secret.
Do not paste a real, live token
An unexpired access token is enough for anyone who gets hold of it to act as you. Even though this tool does not send the token anywhere, use tokens from a test environment or expired tokens rather than ones taken from live systems.
The signature is not verified
What you see here is only the decoded content; it does not mean the token is genuine. The payload is not encrypted, and that nobody has tampered with it is known only if the signature is verified. The optional check covers HS256/384/512 only; RS, ES and PS signatures need a public key and are not verified by this tool.
A token with three parts (header.payload.signature). A leading "Bearer ", quotes and line breaks are removed automatically.
Decoding runs in your browser; the token and secret are not sent anywhere or stored.
For verification at the receiver
- Always verify the signature and take the algorithm from a fixed allow list, not from the token's alg field; this closes alg=none and algorithm-confusion attacks.
- Check exp and nbf with a small tolerance (e.g. 30–60 s); match iss and aud exactly against the expected values.
- Do not put secrets in the payload: a JWT is encoded, not encrypted. Do not write tokens to logs or URLs.
- Use short-lived access tokens and a separate refresh token; have a way to revoke (jti list, key rotation) on logout or suspicion.
This tool only decodes the token and flags known configuration problems; it is not a substitute for signature and content verification, an authorisation decision or a security review. The warning list does not cover all risks. Avoid pasting live-system tokens and production keys into a web page.
Would you like to design authentication, API security and system-to-system integration together? We can talk through token lifetime, key rotation and the permission model.
Request a call01
How to use it
A
Paste a JWT from a test environment (not a live-system token); header and payload open immediately.
B
Look at the time claims, the validity status and the warning list; alg=none, key-location fields and a missing exp are flagged.
C
If the token is HS256/384/512, you can optionally enter the test secret to see whether the signature matches.
02
What a JWT consists of
A JWT (JSON Web Token) is three parts separated by dots: the header (algorithm and type), the payload (the fields, i.e. claims) and the signature. The first two parts are JSON encoded with base64url; the signature is a digest of header and payload signed with a secret or private key.
Encoding is not encryption: anyone can read the payload. The signature only proves that the content has not been changed and that the holder of the key produced the token; it provides no confidentiality.
03
What this tool does and does not do
The tool decodes each part from base64url, reads it as UTF-8 and parses it as JSON; if something is wrong it tells you which part and which line and column. exp, nbf and iat are dates in seconds; the tool shows them in UTC and local time and works out from your browser's clock whether the token has expired.
The signature is not verified by default. The optional check covers HS256, HS384 and HS512 only: an HMAC is computed with the secret over header.payload and compared in constant time. RS, ES, PS and EdDSA need a public key and a separate verification.
04
The most common token mistakes
Accepting alg=none, reading the algorithm from the token, long-lived tokens without exp, secrets written into the payload and skipped iss/aud checks are the most common problems. The jku, x5u and jwk header fields should not be trusted either, as they leave the choice of key source to the token's author.
Most timing problems come from clock skew or a seconds/milliseconds mix-up: exp is in seconds; JavaScript's Date.now() is in milliseconds and must be divided by 1000.
FAQ
- Is my token sent anywhere?
- No. Decoding and the optional HMAC calculation run in your browser; the token and secret are neither sent to a server nor stored. Even so, an unexpired real token is enough to impersonate its owner; do not paste live tokens into any web page, use test tokens.
- Does this tool verify the signature?
- Not by default. Only for HS256/384/512 tokens, and only if you enter the secret yourself, is the signature computed and compared. Public-key signatures such as RS256 and ES256 are not verified here. Seeing a decoded payload does not mean the token is genuine.
- Why is alg=none dangerous?
- alg=none means an unsigned token. If a receiver reads the algorithm from the token and accepts none, an attacker can write the payload as they like and send it without a signature. The fix is to restrict the accepted algorithms at the receiver to a fixed list.
- Why does exp look like a date far in the future?
- NumericDate is in seconds (since 1970-01-01). If the value has 13 digits, it was most likely written in milliseconds and receivers treat it as a date very far away. When issuing tokens, divide Date.now() by 1000.
- Is the information in the payload secret?
- No. A JWT may be signed but it is not encrypted; anyone who decodes the base64url reads the payload. Do not put sensitive data such as passwords or ID numbers in it. If confidentiality is needed, an encrypted JWE is used (a five-part token); this tool cannot decode those.
- Local time and UTC differ, which one is right?
- Both show the same instant. JWT times are moments independent of any time zone; the tool gives UTC and the equivalent in your browser's time zone. Validity is computed from the difference between instants, so the time zone does not change the result.
Let's set up authentication and integrations securely
We design API authentication, token lifetime and key management between CRM, ERP and third-party systems together with you. Let's talk through your current flow in a free discovery call.