Online JWT decoder / parser / signature verifier

Paste a JSON Web Token to split it into Header / Payload / Signature and decode each part into readable JSON, converts exp / iat / nbf times and flags expiry, and verifies HMAC signatures with your key. Everything runs locally in your browser.

Enter a JWT

Waiting for input
A three-part base64url string such as xxxxx.yyyyy.zzzzz, usually from an Authorization: Bearer header.
Algorithm
-
Token type
-
Expiry
-

Header

The Header appears here.

Payload

The payload is a publicly readable set of claims — never put sensitive data in it.
The Payload appears here.

Signature

The Signature appears here.

Signature verification (HS256 / HS384 / HS512)

Enter the same symmetric secret the issuer used; the HMAC is recomputed locally and compared with the signature. Without the key a signature cannot be forged, but note: verifying only proves the token was not tampered with — it does not keep the contents secret.
Enter a secret and press Verify — the result appears here.

A JWT can be read by anyone — that is the point

A JSON Web Token (RFC 7519) is an open way to put JSON inside a URL-safe string. Most often it is a session credential: after you log in, the server issues a token, every later request carries it, and the server can tell who you are and what you may do without a database lookup. Its shape is dead simple — three base64url parts joined by .: a Header naming the algorithm (alg, such as HS256) and type (typ), a Payload holding the claims, and a Signature computed over the first two parts with a key.

base64url differs from ordinary Base64 in only two ways: it swaps + and / for - and _, and drops the trailing = padding, so a token can sit in a URL without being escaped. It is encoding, not encryption — which is exactly why this tool needs no key to turn the Header and Payload back into JSON. The single most important security fact follows from that: the payload is public. Anyone with the token (a browser extension, a log, a proxy, a shared link) can read everything in it, so passwords, phone numbers and ID numbers must never go in.

The signature is about tamper-proofing, not secrecy. The issuer computes an HMAC over Header + Payload with a key; the verifier recomputes it with the same key and compares. Change one character and the signature stops matching. This tool does that with WebCrypto on your device, so the key never leaves it. HS256 / HS384 / HS512 are symmetric (one key signs and verifies); RS256 and friends are asymmetric (private key signs, public key verifies) and suit third-party flows — for those this tool only decodes.

The payload carries standard time claims worth calling out: exp is the expiry, iat the issue time and nbf the not-before time, all in Unix seconds. The classic debugging mistake is reading exp as milliseconds and getting a date a thousand times off — this tool detects seconds versus milliseconds and shows local and UTC time, flagging expired in red and near-expiry (under ten minutes) in amber. Claims iss, aud and sub bound a token to a system; a real verifier must check them too, or a valid token from system A will be accepted by system B.

One long-lived attack deserves knowing: the alg:none downgrade. Early libraries accepted "alg": "none" and skipped verification, so an attacker could swap the signature for none and forge any payload. Mainstream libraries refuse it now, but when auditing your own service make sure there is an algorithm allow-list that accepts only the expected alg rather than trusting whatever the token claims. Decoding here is done in your browser; your token never reaches a server.

Frequently asked questions

Is my JWT sent to a server when I decode it?

No. Decoding happens entirely in your browser with JavaScript, so the token never leaves your device. That is why you can safely inspect a real token here.

Can anyone read the data inside a JWT?

Yes. The Header and Payload are only Base64url-encoded, not encrypted, so anyone who has the token can read them. Never put passwords, phone numbers or other secrets in the payload.

What does the signature verification do?

For HMAC algorithms (HS256 / HS384 / HS512) it recomputes the signature from the Header and Payload using the secret you enter and compares it with the token. A match proves the token was not tampered with with that key. Asymmetric algorithms such as RS256 can be parsed but not verified locally.

Why does my exp look like the wrong date?

exp is usually a Unix timestamp in seconds, not milliseconds. A 10-digit value is seconds and a 13-digit value is milliseconds; the tool detects which and shows both local and UTC time.