About this tool
JWT Decoder separates a JSON Web Token into its Base64URL header, payload, and signature segments. It displays the first two parts as readable, formatted JSON and lists registered claims including issuer, subject, audience, expiry, not-before time, issued-at time, and token identifier whenever those values are present.
Time claims appear as a local date plus a relative description, and the status badge reports Valid, Expired, Not yet valid, or No expiry. For HS256, HS384, and HS512 tokens, enter the shared secret to verify the HMAC signature with Web Crypto. RSA, ECDSA, and PSS algorithms are decoded but not verified here.
How to use the JWT Decoder
- 1Paste a token containing header, payload, and signature segments.
- 2Read the formatted header and payload JSON in their separate panels.
- 3Review registered claims, local dates, relative times, and the status badge.
- 4Enter a shared secret when the token uses HS256, HS384, or HS512.
- 5Copy decoded JSON or inspect the original signature segment as needed.
Features
UTF-8 Base64URL decoding
Decode non-ASCII JSON safely while validating the alphabet and structure of each token segment.
Registered claims table
Collect issuer, subject, audience, three time claims, and token identifier into a focused summary.
Relative expiry status
Combine local claim dates with phrases such as expires in two hours or expired three days ago.
Web Crypto HMAC check
Verify HS256, HS384, and HS512 signatures against a secret without transmitting either value.
Algorithm guidance
Warn about unsigned none tokens and explain when RSA, ECDSA, or PSS verification is unsupported.
Frequently asked questions
Does decoding a JWT prove that it is trustworthy?
No. Anyone can Base64URL-decode the header and payload. Trust requires a valid signature, suitable key handling, and application-specific claim checks.
Which JWT signatures can this page verify?
It checks HMAC tokens using HS256, HS384, or HS512 and a shared secret. RS, ES, and PS families are displayed but not verified.
What does the No expiry badge mean?
The payload has no numeric exp claim. The token may still be limited by server state, another claim, or an application's own rules.
Why does the decoder report a header or payload error?
That segment may contain an invalid Base64URL character, invalid UTF-8 text, or content that is not a JSON object.
Is my token uploaded when I decode or verify it?
No. Parsing and Web Crypto signature checking occur in the browser, but you should still avoid placing production credentials into unfamiliar sites.