JWT Decoder
Decode a JSON Web Token's header and payload, and optionally verify its HMAC signature.
How to Decode a JWT
- Paste a JWT into the box — it decodes instantly as you type.
- Review the decoded header and payload as formatted JSON.
- Check the expiry status shown below.
- Optionally enter the HMAC secret to verify the signature is valid.
Frequently Asked Questions
Is decoding a JWT the same as verifying it's genuine?
No. The header and payload of a JWT are only base64url-encoded, not encrypted, so anyone can decode and read them without any secret. Verifying that a token is genuine and untampered requires checking its signature against the secret or public key that issued it, which is a separate step this tool only performs if you provide the correct HMAC secret.
Is my token sent anywhere when I paste it in?
No — decoding and signature verification both happen entirely in your browser using standard JavaScript and the Web Crypto API. Nothing about your token, including any secret you enter for verification, is ever sent to a server.
Why does the signature verification only work for HMAC (HS256/HS384/HS512) tokens?
HMAC algorithms use a single shared secret for both signing and verifying, which this tool can check directly once you provide that secret. RSA and ECDSA algorithms (RS256, ES256, and similar) use a public/private key pair instead — verifying those would require the issuer's public key, which is a more involved setup this simple tool doesn't currently support.
What does the "exp" field in the payload mean?
exp stands for "expiration time" — a Unix timestamp after which the token should no longer be considered valid. This tool converts it to a readable date and flags whether the token has already expired relative to your current system clock.