The secret stays in this page. Nothing is sent anywhere — but a production signing key is still worth being careful with.

Good to know

  • A JWT is signed, not encrypted. Anyone holding the token can read the payload exactly as this page does, so nothing secret belongs in it.
  • Reading a token proves nothing about it. Only the signature does, and only HS256, HS384 and HS512 can be checked here — the rest need the issuer's public key.
  • exp, nbf and iat are seconds since 1970, not milliseconds. A token that seems to expire in 1970 is usually a millisecond value that was pasted in.
  • Everything happens in your browser. The token and the secret are never sent to the server or stored anywhere.
27 views
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.