Free tool · runs in your browser

🔑 JWT Decoder & Verifier

Paste a JSON Web Token to decode its header and claims, see when it expires, spot security problems, and verify the signature with your secret or public key. Everything happens in your browser.

Decodes as you type. Nothing is sent anywhere.

Runs in your browser: what you enter is never sent anywhere. We only count anonymous usage, such as which buttons are used, to improve the tools.

What’s inside a JWT

A JSON Web Token has three base64url parts separated by dots: a header naming the signing algorithm, a payload of claims about the user or session, and a signature that proves the first two weren’t changed. Registered claims such as exp (expiry), iat (issued at), iss (issuer) and aud (audience) are standard; anything else is application-specific.

Common JWT mistakes

  • Accepting alg: none, or trusting the token’s own alg header instead of pinning the algorithm you expect.
  • Long-lived access tokens without expiry. Keep access tokens short (minutes) and use refresh tokens.
  • Storing secrets or personal data in the payload, which anyone holding the token can read.
  • Weak HS256 secrets that can be brute-forced. Use at least 32 random bytes.

Frequently asked questions

Is it safe to paste my JWT here?

Yes. Decoding and verification run entirely in your browser with JavaScript and the Web Crypto API. The token, secret and key are never sent anywhere. Still, treat production tokens as credentials and prefer expired or test tokens when you can.

Can anyone read the data inside a JWT?

Yes. A standard signed JWT (JWS) is only base64url-encoded, not encrypted. Anyone holding the token can read the header and payload, so never put passwords or other secrets in it. The signature only proves the token hasn’t been changed.

What is the difference between HS256 and RS256?

HS256 signs with a shared secret, so every service that can verify a token can also create one. RS256 signs with a private key and verifies with a public key, so verifiers can’t forge tokens. Use RS256 or ES256 when several services verify tokens.

How do I verify a JWT in PHP?

Use a maintained library such as firebase/php-jwt or lcobucci/jwt. Always pin the expected algorithm, verify the signature, and check exp, nbf, iss and aud. Never trust the alg value from the token header on its own.