How to use the JWT Decoder & Verifier
- Paste your token into the box. A leading
Beareris removed automatically. - Read the decoded header and payload. The status line shows whether the token has expired.
- Check the Claims table for what each field means, with dates converted from Unix time.
- To verify the signature, paste the shared secret (HS256) or the public key as PEM or JWK (RS256, ES256 and others).
What's inside a JWT?
A JSON Web Token has three parts separated by dots: header.payload.signature. The header says which algorithm signed the token. The payload holds the claims: who the user is, what they can do and when the token expires. The signature proves the first two parts haven't been changed.
The header and payload are only Base64URL-encoded, not encrypted. Anyone holding the token can read them, so never put passwords or secrets in a JWT payload.
Standard claims
iss(issuer): who created the token, usually your login server.sub(subject): the user or thing the token is about.aud(audience): which app or API should accept it.exp(expiration),nbf(not before) andiat(issued at): times in Unix seconds, shown here as readable dates.jti(JWT ID): a unique ID that helps prevent replay.
Decoding is not verifying
Anyone can create a token with any payload. Your server must always verify the signature with the right key and check exp, iss and aud before trusting it. Reject tokens with "alg": "none". Use this page to debug tokens, never as a replacement for server-side checks.
Frequently asked questions
Is it safe to paste my JWT here?
Decoding and verification run entirely in your browser; the token isn't sent anywhere. Still, treat live tokens like passwords and prefer test tokens when you can.
Why does it say 'Invalid signature'?
The key doesn't match the one used to sign the token, the token was modified, or (for HS256) the secret is Base64-encoded and needs the <b>Secret is Base64-encoded</b> box ticked.
Which algorithms can be verified?
HS256, HS384, HS512, RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384, ES512 and EdDSA (Ed25519, in browsers that support it).
Can I use a JWKS URL?
Download the JSON from the URL and paste it. If it contains several keys, the one matching the token's <code>kid</code> is used.
Can it decrypt JWE tokens?
No. Encrypted tokens (five parts) need the private decryption key. The decoder shows their header only.