JWT Decoder & Verifier
Decode a JSON Web Token’s header and payload, check its expiry and verify HMAC signatures — locally in your browser.
Decoded locally. The token is never sent to a server or saved in your browser.
Header
—
Payload
—
Claims
| Paste a token to see its claims. |
Verify signature
Enter the secret to check the signature.
How to use the JWT Decoder
- Paste a JWT (three dot-separated parts) into the token box.
- Read the decoded header and payload. Time claims are shown as dates with a live expiry status.
- For HS256, HS384 or HS512 tokens, enter the shared secret to verify the signature.
- Copy the decoded JSON for use in tests or bug reports.
What is a JSON Web Token (JWT)?
A JSON Web Token is a compact, URL-safe way to pass claims between two parties, defined in RFC 7519. It is the most common format for access tokens issued by OAuth 2.0 and OpenID Connect providers such as Auth0, Okta, Cognito, Firebase and Keycloak, and for session tokens in single-page apps and APIs.
A JWT has three Base64URL-encoded parts separated by dots:
header.payload.signature
- Header — metadata such as the signing algorithm (
alg), token type (typ) and key ID (kid). - Payload — the claims: who the token is about (
sub), who issued it (iss), who it is for (aud), when it expires (exp) plus any custom data such as roles or scopes. - Signature — a cryptographic signature over the header and payload, so the receiver can detect tampering.
Decoding is not verifying
The header and payload are only encoded, not encrypted. Anyone who holds a token can read its claims — which is exactly what this decoder does — so never put secrets such as passwords in a JWT payload. A server must verify the signature with the correct key before trusting any claim, and must check exp, nbf, iss and aud. Reject tokens with "alg": "none", and never let the token’s own header choose a weaker algorithm than the one you expect.
Registered claims at a glance
| Claim | Name | Meaning |
|---|---|---|
iss | Issuer | Who created and signed the token |
sub | Subject | The user or entity the token is about |
aud | Audience | The API or client that should accept it |
exp | Expiration | Unix time after which it must be rejected |
nbf | Not before | Unix time before which it must be rejected |
iat | Issued at | Unix time it was created |
jti | JWT ID | Unique ID, useful for revocation and replay protection |
HMAC vs. public-key signatures
HS256, HS384 and HS512 use one shared secret to both sign and verify, so every service that verifies tokens can also mint them. RS256, ES256 and PS256 sign with a private key and verify with a public key, usually published by the identity provider as a JWKS document. This tool verifies HMAC tokens in the browser using the Web Crypto API; public-key tokens are decoded and their algorithm is shown.
Time claims are Unix timestamps — convert any of them with the Unix Timestamp Converter.
Frequently asked questions
Is it safe to paste a production token here?
Does decoding a JWT mean it is valid?
exp, nbf, iss and aud claims are checked.Which algorithms can be verified?
What do exp, nbf and iat mean?
exp is when the token expires, nbf is the time before which it must not be accepted, and iat is when it was issued. All three are Unix timestamps in seconds.Why does my token fail to decode?
Bearer prefix copied with it, or whitespace and line breaks inside the token. Bearer prefixes and whitespace are stripped automatically.Last updated . Launched with claim timeline and HS256/384/512 signature verification.
Building something that needs live data?
ProWebLook APIs validate phone numbers, check WhatsApp accounts, verify emails and geolocate IPs. Try every endpoint in the browser, then grab a free API key.