How to decode a JWT
- 1.
Paste the token
Paste the whole token (a “Bearer ” prefix is fine). Header and payload are decoded instantly.
- 2.
Check validity
See exp, iat and nbf as readable dates with relative time and whether the token has expired.
- 3.
Verify the signature
Enter the secret (HS256/384/512) or a PEM/JWK public key (RS, PS, ES) to confirm the token was not tampered with.
JWT structure
A JWT (RFC 7519) has three base64url-encoded parts separated by dots: header.payload.signature. The header holds the signing algorithm, the payload holds claims such as sub, iss, exp and iat, and the signature protects against modification. Header and payload are only encoded, not encrypted - never put secrets in them.
Never paste production tokens into unknown websites. This tool works locally and sends nothing anywhere, but treat tokens like passwords.
Standard claims: exp, iat, nbf, iss, sub, aud
| Claim | Meaning | Example |
|---|---|---|
exp | expiry time | 1767225600 = 1 Jan 2026, 00:00 UTC |
iat | issued at | Unix seconds |
nbf | not valid before | Unix seconds |
iss | issuer | https://auth.example.com |
sub | subject (usually user ID) | user_123 |
aud | intended audience | api.example.com |
jti | unique token ID | a UUID |
Timestamps are seconds since 1 January 1970 UTC, not milliseconds. A token issued at 1767225600 with a 15-minute lifetime has exp = 1767225600 + 900 = 1767226500. The decoder converts them to local and UTC dates and shows the remaining time.
Verifying the signature: HS256 vs RS256 vs ES256
- HS256/384/512 - HMAC with one shared secret. Anyone who can verify the token can also create one, so the secret must stay on the server.
- RS256/384/512 and PS256/384/512 - RSA key pair. The issuer signs with the private key; anyone can verify with the public key, often published as a JWKS.
- ES256/384/512 - elliptic-curve keys; much shorter signatures than RSA with comparable security.
Paste the public key as PEM (-----BEGIN PUBLIC KEY-----) or as a JWK object. X.509 certificates and PKCS#1 keys (RSA PUBLIC KEY) are not accepted - extract or convert the key first, e.g. openssl x509 -pubkey -noout. If the secret is base64url-encoded, tick the matching option.
Common reasons a signature fails
- Wrong secret or key, or one with a stray space or newline.
- A base64-encoded secret entered as plain text (or the other way round).
- The token was copied incompletely - all three parts are required.
- The token header says
alg: none- it has no signature and must never be trusted.
Decoding alone proves nothing: always verify the signature on the server before trusting any claim.
Frequently asked questions
Is it safe to paste a JWT here?
+
Is a JWT encrypted?
+
Which algorithms can be verified?
+
How do I check if a JWT has expired?
+
What is the difference between HS256 and RS256?
+
Why does verification say the signature is invalid?
+
Updated: