Decode
A JWT has three dot-separated parts — header, payload, signature — each Base64URL-encoded. This tool decodes the header and payload to readable JSON and converts exp, iat and nbf timestamps into human dates so you can see when a token was issued and when it expires.
Verify (HS256)
Decoding never needs the secret — anyone can read a JWT's contents. To confirm a token is authentic, enter the shared secret and verify: the tool recomputes the HMAC-SHA256 signature with the Web Crypto API and compares it. RS/ES (asymmetric) algorithms aren't verified here.
Privacy
The token and secret stay in your browser — never uploaded. Still, don't paste production secrets into a machine you don't trust.