Skip to content
Accessibility
Theme
Text size
High contrast
Limit animations
Readable fontAtkinson Hyperlegible
Increased text spacing
Underline links
Always show focus

Runs in your browser — nothing you paste is uploaded.

JWT Decoder

Decode a JSON Web Token to inspect its header and payload, with readable expiry times. Optionally verify an HS256 signature. Everything runs in your browser — the token never leaves this page.

Paste a token. Decoding does not require the secret.


      

Decode

A JWT has three dot-separated parts — header, payload, signature — each Base64URL-encoded. This tool decodes the header and payload to readable JSON and converts exp, iat and nbf timestamps into human dates so you can see when a token was issued and when it expires.

Verify (HS256)

Decoding never needs the secret — anyone can read a JWT's contents. To confirm a token is authentic, enter the shared secret and verify: the tool recomputes the HMAC-SHA256 signature with the Web Crypto API and compares it. RS/ES (asymmetric) algorithms aren't verified here.

Privacy

The token and secret stay in your browser — never uploaded. Still, don't paste production secrets into a machine you don't trust.

Frequently asked questions

Does decoding a JWT prove it's genuine?

No. Decoding only reads the unencrypted header and payload. Use the HS256 verify option with the shared secret to confirm the signature.

Is it safe to paste a token here?

The token and secret stay in your browser and are never uploaded. Still, avoid pasting long-lived production secrets on a machine you don't fully trust.

Related tools