How do I decode a JWT?
Paste the token into the box above. The tool splits it at the dots, decodes the header and payload from Base64URL and shows them as formatted JSON. You can paste a raw token, a token with a 'Bearer ' prefix, or a whole Authorization header.
What is a JWT?
A JSON Web Token is a compact, URL-safe way to pass claims between two parties. It has three parts separated by dots: a header that names the signing algorithm, a payload that holds the claims (such as who the user is and when the token expires), and a signature that proves the first two parts haven't been changed.
Does decoding a JWT prove it is genuine?
No. The header and payload are only encoded, not encrypted, so anyone can read them and anyone can make a token that looks real. Only the signature check tells you whether the token was issued by someone who holds the right key. Open the 'Verify signature' panel and enter the secret or public key to check it.
Is my token sent anywhere?
No. Decoding and verification both run in your browser using JavaScript and the Web Crypto API. Nothing is uploaded or stored, so it's safe to paste real tokens and keys. Even so, treat live production tokens with care, as they can grant access until they expire.
Which signing algorithms can it verify?
HS256, HS384 and HS512 (shared secret), RS256, RS384 and RS512 (RSA), PS256, PS384 and PS512 (RSA-PSS), and ES256, ES384 and ES512 (ECDSA). For the asymmetric algorithms, paste a public key in PEM format (-----BEGIN PUBLIC KEY-----) or as a JWK. A JWKS document also works: the tool picks the key whose kid matches the token.
What does 'alg: none' mean?
It marks an unsigned token. Servers should always reject these, because anyone can create one. If you see this warning on a token from a real service, treat it as a security problem.
How do I read the expiry time?
The exp, nbf and iat claims are Unix timestamps in seconds. The 'Claims explained' section converts them to your local time and to UTC. To convert any other timestamp, use the timestamp converter.