JWT Decoder
Decode JWTs to read claims and expiry, and check HS256 signatures, without sending the token anywhere.
Decoding is not verification. Anyone can read a JWT and change its contents. Only a signature check with the right key shows that it is genuine.
HeaderPayloadSignature
Header
{
"alg": "HS256",
"typ": "JWT"
}Payload
{
"sub": "user_8231",
"name": "Asha Verma",
"email": "asha@example.in",
"role": "admin",
"iat": 1791397193,
"exp": 1791401093
}Claims
| Claim | Value |
|---|---|
subSubject | user_8231 |
nameName | Asha Verma |
emailEmail | asha@example.in |
roleRole | admin |
iatIssued at | 17913971937 Oct 2026, 11:49:53 pm IST5 minutes ago |
expExpires | 17914010938 Oct 2026, 12:54:53 am ISTin 1 hour |
Signature
pdRXlsCYHX8bm7MSZPUtYC5v5gY6Vyx6S2WErtNE8sIThe secret stays on this page. Never paste a production secret on a shared computer.
Signature verified with this secret (HS256).
JWT Decoder FAQ
How do I decode a JWT?
Paste the token into the Token box. The header and payload appear as formatted JSON, and the Claims table lists each claim with a short explanation. You can paste it with or without the "Bearer " prefix.
How do I check if a JWT is expired?
Look at the status next to alg and typ: it says, for example, "Expired 3 hours ago" or "Not expired: expires in 2 days". The exp row in Claims shows the exact expiry in IST and in your own time zone.
Does decoding a JWT verify it?
No. The header and payload are only Base64url-encoded, so anyone can read or change them. A token is genuine only if its signature checks out with the right key. Here you can check HS256, HS384 and HS512 tokens with their secret.
How do I verify an HS256 signature?
Paste the token, then type the shared secret in the Signature section. The tool recomputes the HMAC and says "Signature verified" or "Invalid signature". If your secret is stored as Base64, turn on "Secret is Base64-encoded".
Is it safe to paste my token here?
The token and secret are processed in your browser and are not uploaded or saved. Still, a valid token works like a password until it expires, so avoid pasting live production tokens on shared or public computers.
What is the difference between JWS and JWE?
Most JWTs are JWS: signed, three parts, readable by anyone. A JWE is encrypted, has five parts, and only the intended recipient can read its payload. This tool decodes JWS tokens and explains when it sees a JWE.