Search tools

JWT Decoder

Read a JSON Web Token’s header and claims, and verify it with your key.

Tokens & Certificates

JWT

Decoded is not verified

  • Header and claims: The header and payload are decoded from Base64URL and shown as JSON; exp, nbf and iat are read as dates.
  • Verify with your key: A shared secret (HS256 to HS512), a public key or certificate in PEM, or a JWK checks the signature. alg none is never accepted, and a key must fit the algorithm.
  • Treated as a secret: A token is never shown in suggestions, titles or announcements, never stored, and gone when you leave. No key or JWKS is fetched.

Frequently asked questions

Does a decoded token mean it is genuine?

No. Anyone can write a token that decodes. Only a valid signature with the issuer’s key shows who made it, and even then issuer, audience and times decide whether to trust it.

Why is my token not valid yet or expired?

The times are compared with this device’s clock. exp and nbf are shown separately from the signature result.

Can it decrypt an encrypted token (JWE)?

No. An encrypted token has five parts and needs its key to decrypt; it is named, not opened.