webtrajans
en

JWT Decoder

Decode the header and payload of any JSON Web Token, see when it expires, and verify HMAC signatures — without the token leaving your browser.

⚠ The token is decoded only in your browser. Still, never paste real production tokens into any web tool.

Header

Time claims

Payload

Verify signature (HMAC)

This tool runs entirely in your browser; your data is never sent to a server.

How to use

  1. 1Paste a JWT; a leading “Bearer ” is removed automatically.
  2. 2Read the decoded header and payload as formatted JSON.
  3. 3Check the time claims: exp, iat and nbf are shown as dates with an Expired, Valid or Not valid yet label.
  4. 4To verify an HS256, HS384 or HS512 signature, enter the secret (tick the box if it is base64 encoded).

Anatomy of a JWT

A JSON Web Token (RFC 7519) has three base64url-encoded parts separated by dots: header.payload.signature. The header names the signing algorithm (alg, e.g. HS256 or RS256) and the token type; the payload holds claims such as sub (subject), iss (issuer), aud (audience) and the time claims exp (expiry), iat (issued at) and nbf (not before), all in Unix seconds. The decoder turns those timestamps into readable dates with relative times such as “in 3 hours”. Remember that the payload is only encoded, not encrypted: anyone holding the token can read it, so never put secrets in claims.

Verifying the signature

Decoding proves nothing about authenticity — only the signature does. For HMAC algorithms (HS256, HS384, HS512), enter the shared secret and the tool recomputes the signature with the browser’s Web Crypto API and compares it with the token. Asymmetric algorithms such as RS256 or ES256 need the issuer’s public key and are not verified here. A token with alg “none” is flagged: it carries no signature, and a server must never accept it.

Handling tokens safely

Decoding and verification run entirely in your browser; nothing is sent to a server. Even so, a valid access token works like a password until it expires, so avoid pasting live production tokens or signing secrets into any web tool. Use test tokens, or tokens that have already expired, when debugging.

Frequently asked questions

Can a JWT be decoded without the secret?

Yes. The header and payload are just base64url-encoded JSON, so anyone can read them. The secret is only needed to create or verify the signature.

How do I check if a JWT is expired?

Look at the exp claim, the expiry time in seconds since January 1, 1970 (UTC). The decoder converts it to a date and shows an Expired label once that time has passed.

Why does it say “Invalid signature”?

The secret is wrong, contains extra whitespace, or is base64 encoded and needs the base64 option ticked — or the token was changed after it was signed.

Is a JWT encrypted?

A normal signed JWT (JWS) is not: anyone can read it. Only an encrypted JWT (JWE, with five parts) hides its contents. This tool decodes signed three-part tokens.

Not happy with the results?

Talk to Webin Agency about fast, SEO-friendly websites, e-commerce and Google Ads management.

Get free advice

Related tools