JWT Decoder
Decodes JSON Web Tokens, explains the claims, and verifies HS, RS, PS, and ES signatures.
A JWT verify signature tool for when decoding is not enough: check the signature with a secret, a PEM public key, a JWK, or a whole JWKS, then see the time claims on a timeline and the warnings a careful reviewer would raise.
Decodes as you paste. A "Bearer " prefix is removed for you.
For HS256, HS384, and HS512, the shared secret. For RS, PS, ES, and EdDSA, a PEM public key, a JWK, or a whole JWKS (the key is picked by kid).
You get the header and claims in plain JSON, a timeline of when the token is valid, and a signature check once you add the key.
| Claim | Value | Meaning |
|---|
Bearer is removed for you.A JWT is three Base64URL parts joined by dots: a header, a payload, and a signature over the first two. The inspector decodes the header and payload, imports your key into the browser's Web Crypto API, and asks it to check the signature against the exact bytes header.payload.
When the key is a JWKS, the key whose kid equals the token's kid is used. Keys marked "use": "enc" are skipped, and a key whose own alg differs from the token's is refused. A token with no kid works only when exactly one key fits its algorithm.
The timeline places iat, nbf, exp, and the current time in order. With a skew of 60 seconds, a token that expired 30 seconds ago still counts as valid, the same allowance most JWT libraries make.
The sample is the token from the jwt.io debugger:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
With the secret your-256-bit-secret the signature is valid. Two warnings remain. The secret is 19 bytes, while HS256 should use at least 32 random bytes. The payload has no exp, so the token never expires.
Change one letter of the secret and the result turns to Invalid signature, because HMAC gives a completely different value for a different key.
| Warning | Why it matters |
|---|---|
| alg is none | The token carries no signature. A server that accepts it lets anyone write their own claims. |
| Short HMAC secret | RFC 7518 asks for a key at least as long as the hash. A short secret can be guessed offline from a single token. |
| No exp | A stolen token keeps working until the signing key changes. |
| jku, x5u, or jwk in the header | The token points at its own key. A verifier must use keys it already trusts, never ones the token supplies. |
| exp looks like milliseconds | JWT times are seconds since 1970. A value in milliseconds puts the expiry thousands of years ahead. |
jwks_uri and paste it.RSA PUBLIC KEY blocks are not read. Convert them to a PUBLIC KEY PEM with OpenSSL first.The JWT Decoder reads a token and checks it with one key. The inspector also picks the key from a JWKS by kid, applies a clock skew, and lists security warnings.
The token and the key stay in your browser and are not sent anywhere. Even so, prefer a public key or a test secret, and never paste a private key into any website.
A valid signature only proves who made the token and that it was not changed. An unsigned algorithm, a weak secret, or a token that never expires are separate problems.
Use the leeway your own service allows. The jsonwebtoken package for Node.js and PyJWT allow none unless you set it, while .NET's token validation allows five minutes by default.
Often used together with JWT Inspector.
Decodes JSON Web Tokens, explains the claims, and verifies HS, RS, PS, and ES signatures.
Signs text or files with HMAC-SHA256 and other hashes, and checks signatures.
Creates RSA key pairs as PEM, OpenSSH, and JWK, entirely in the browser.