JWT Decoder
Read a token's header and payload, check when it expires, verify an HMAC signature.
The secret stays in this page. Nothing is sent anywhere — but a production signing key is still worth being careful with.
Result
Good to know
- A JWT is signed, not encrypted. Anyone holding the token can read the payload exactly as this page does, so nothing secret belongs in it.
- Reading a token proves nothing about it. Only the signature does, and only HS256, HS384 and HS512 can be checked here — the rest need the issuer's public key.
- exp, nbf and iat are seconds since 1970, not milliseconds. A token that seems to expire in 1970 is usually a millisecond value that was pasted in.
- Everything happens in your browser. The token and the secret are never sent to the server or stored anywhere.
27 views