Decode any JWT in your browser
Paste a token to read its header and payload, see when it expires, and check an HMAC signature. Nothing is sent to a server.
Runs locallyHS256 · HS384 · HS512Free, no sign-up
Questions
Is it safe to paste a production token?
Decoding happens in your browser with JavaScript. The token is never uploaded or stored. Still, treat live tokens as secrets and prefer test tokens when you can.
Does decoding prove a token is valid?
No. Anyone can read a JWT's contents. Only a signature check with the right secret or public key proves it was not changed.
Which algorithms can I verify?
HS256, HS384 and HS512 with a shared secret. RSA and ECDSA verification is coming soon.