Tools marked “Coming soon” are being built now.

Developer tools
Developer · Free · Private

JWT Decoder

Paste a token to see what it says, when it expires and whether its signature holds up. It never leaves this page.

  • Runs in your browser
  • No upload
  • No sign-up

Tokens and keys are decoded, checked and signed on this page only. Nothing is sent anywhere, so it is safe to paste a real one.

About this tool

A JSON Web Token (JWT) is the long string starting “eyJ” that apps use to prove who you are: in a login cookie, an Authorization: Bearer header or an OAuth sign-in. It has three parts separated by dots. The header says how it was signed, the payload holds the claims (who it is for, who issued it, when it expires) and the signature proves nobody changed it. The first two parts are only encoded, not encrypted, so anyone holding the token can read them.

Paste a token and this decoder colour-codes the three parts, shows the header and payload as tidy JSON, and explains every known claim in a sentence. Times appear as dates in your own time zone with “expires in 3 hours” beside them, and a banner says straight away whether the token is still usable. It warns about alg “none”, missing algorithms and times written in milliseconds.

To be sure a token is genuine, check its signature: type the shared secret for HS256, HS384 or HS512, or paste the public key (PEM, certificate, JWK or a whole JWKS key set) for RSA, RSA-PSS, ECDSA and Ed25519 tokens.

The “Create & sign” tab works the other way round, for testing your own API: write the claims, set iat, nbf and exp with one click, and sign with a secret or a private key, or generate a fresh key pair and copy its public key as PEM or JWKS. Everything runs in your browser’s built-in cryptography, so tokens and keys are never sent anywhere.

How to use JWT Decoder

  1. Paste your token into “Paste a JWT”, or press “Paste”. A leading “Bearer ” or quotes are removed for you. “Try an example” loads a sample.
  2. Read the banner first: green means not expired, red means expired, amber means not valid yet.
  3. Look at the Header and Payload panels for the raw JSON, and press “Copy JSON” to take either away.
  4. Read “What each part means” for every field in plain English, with dates in your time zone.
  5. Under “Check the signature”, type the secret or paste the public key. The result appears as you type.
  6. To make a token, open “Create & sign”, pick the algorithm, edit the payload, press “Generate secret” or “Generate key pair”, then “Copy” (or “Check it” to see it verified).
Example

A token with "exp": 1767225600 shows as midnight on 1 January 2026 (UTC), converted to your time zone, with “expired 9 months ago” in early October 2026 and a red banner, before you check anything else.

Features

  • Colour-coded header, payload and signature, with readable dates beside exp, iat, nbf and auth_time.
  • Plain-English meanings for more than 50 standard and common claims and header fields, including OpenID Connect, OAuth and Microsoft Entra ones.
  • Live expiry banner that keeps updating while the page is open, plus the token’s lifetime.
  • Warnings for alg “none”, a missing alg, times in milliseconds and tokens issued in the future.
  • Signature check for HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512 and EdDSA (Ed25519, in browsers that support it).
  • Public keys as PEM, X.509 certificate, JWK, or a JWKS key set: the key is picked by kid, or every key is tried when the token has none.
  • Create and sign tokens with HS256/384/512, RS256/384/512, PS256/384/512 or ES256/384/512, with one-click iat, nbf, exp and jti.
  • Sign with a PEM private key (PKCS#8, RSA or EC), a private JWK, a random secret of the right length, or a new key pair, with its public key as PEM and as a JWKS whose kid is the key’s RFC 7638 thumbprint. Weak keys get a warning.
  • Clear messages for encrypted (JWE), cut-off or broken tokens.

Tips and good to know

  • Decoding is not verifying. Anyone can make a token that decodes to any claims, so only trust the claims after the signature check is green.
  • Anyone holding a JWT can read its payload, so never put passwords or private details in one.
  • An issuer’s public keys are usually at an address ending /.well-known/jwks.json. Paste the whole set.
  • If an HS256 check fails with the right secret, the secret may be stored Base64url-encoded. Switch to “Secret is Base64url”.
  • Generated private keys exist only on this page: save one if you need it again.

Frequently asked questions

Is my token sent anywhere?

No. Tokens, secrets and keys stay on this page. Checking and signing use your browser’s built-in Web Crypto, so nothing is uploaded, logged or stored.

Is it free? Are there limits?

It is free, with no sign-up, and you can decode, check and sign as many tokens as you like.

Does it work on a phone or offline?

Yes. It works in Safari, Chrome and Firefox on phones and computers, and keeps working offline once the page has loaded.

Can I decode a JWT without the secret?

Yes. The header and payload are only Base64url-encoded, so they can always be read. A key is needed only to prove the token is genuine.

Why does it say my token is expired?

The exp claim is the moment the token stops being valid, in seconds since 1970, compared with your device’s clock. If your clock is wrong, the result will be too.

What does alg “none” mean and why is it dangerous?

The token has no signature, so anyone could have written it. Some old libraries accepted such tokens, letting attackers forge logins, so servers must reject it. “Create & sign” never makes one.

Can it read encrypted tokens (JWE)?

No. A JWE has five parts and its payload is encrypted for the receiver. The tool shows its header, but the contents need the receiver’s private key.

Page last reviewed