About the JWT Decoder
A JWT (RFC 7519) has three Base64url parts separated by dots: a JSON header (alg, typ, kid), a JSON payload of claims, and a signature. The header and payload are only encoded, not encrypted, so anyone holding the token can read them — never put secrets in a JWT payload. A 5-part token is a JWE, which is encrypted and cannot be read without its key.
The decoder shows both parts as highlighted JSON and converts the registered time claims — iat (issued at), nbf (not before) and exp (expires) — from Unix seconds into local and UTC time, with a chip telling you whether the token is currently valid, not yet valid or expired. A leading Bearer is ignored, so you can paste an Authorization header value directly.
Decoding says nothing about authenticity, so the tool also verifies the signature with the Web Crypto API. For HS256, HS384 and HS512 enter the shared secret, as text or Base64. For RS256/384/512 (RSA PKCS#1 v1.5), PS256/384/512 (RSA-PSS) and ES256/384/512 (ECDSA on P-256, P-384 and P-521) the field switches to a public key: paste a PEM public key, a PEM certificate, a JWK or a whole JWK Set, from which the key with the kid of the token is taken. The key type and curve are checked against alg, and tokens with alg: none are flagged. Nothing is sent to a server.
How to use it
- Paste the token (with or without “Bearer ”).
- Read the header, payload and time claims, and check the expiry chip.
- For an HS* token, type the secret in the Signature panel.
- For an RS*, PS* or ES* token, paste the public key (PEM, certificate or JWK).
Frequently asked questions
Is it safe to paste a production JWT here?
Why does my token show as expired when it just worked?
How do I verify an RS256 or ES256 token?
-----BEGIN PUBLIC KEY----- block, a certificate, or a JWK. Issuers publish their keys at a JWKS endpoint (often /.well-known/jwks.json); you can paste the whole JSON and the key matching the token's kid is used.Why is the signature invalid with the right secret or key?
kid: issuers rotate keys. In both cases the token must not have been altered or re-encoded.