Developer Tools

JWT Decoder

Paste a JSON Web Token to read its header and claims, see a live countdown to when it expires, and optionally verify the signature with your secret or public key. Everything runs locally in your browser — safe for real tokens.

JWT Decoder

Free · No sign-up
Loading tool…

Frequently asked questions

Is it safe to paste a real token here?

Yes. Decoding and verification happen entirely in your browser with the Web Crypto API. The token, secret and key are never sent to any server — you can check this in your browser's Network tab.

Does decoding a JWT prove it's genuine?

No. Anyone can read a JWT's header and payload — they're only base64url-encoded, not encrypted. Only a successful signature verification with the right secret or public key proves the token wasn't forged or changed.

Which algorithms can it verify?

HS256/384/512 (with the shared secret), RS256/384/512 and PS256/384/512 (RSA public key) and ES256/384/512 (EC public key). Keys must be in PEM “BEGIN PUBLIC KEY” format.

How is the expiry calculated?

From the exp (expires at) and nbf (not before) claims, which are seconds since 1970 (Unix time), compared with your device's clock. Times are shown in your local time zone.

Why does it say the token is encrypted (JWE)?

Tokens with five dot-separated parts are encrypted JWEs, not signed JWTs. Their contents can only be read with the decryption key, so they can't be decoded here.

What does “alg: none” mean?

The token has no signature at all, so anyone could have created or modified it. Production servers should always reject unsigned tokens.