Developer

JWT Decoder

Decode JSON Web Tokens, check their times and, optionally, their signature with your own key, offline.

Token

About this tool

Paste a JSON Web Token to read its header and claims. Expiry (exp), not-before (nbf) and issued-at (iat) times are shown in your time zone and in UTC, and checked against your clock, with warnings for times written in milliseconds or tokens that aren’t signed at all.

Decoding a token proves nothing about it: anyone can make one that decodes the same way. To check the signature, paste the shared secret for HS256, HS384 and HS512, or a public key, certificate, JWK or key set for RS, PS, ES and EdDSA tokens. Checking happens in your browser with the Web Crypto API.

Tokens and keys stay on this page. They aren’t saved, put in the address bar or sent anywhere, and keys referenced by the token (jku, x5u) are never downloaded.

Why does it say “not verified” for a token my app accepts?

Because nothing has checked it here yet. Your app checks signatures with its key; paste that key (public keys are safe to share) to check it on this page too.

esc
  • Opens in its own window, like any app
  • Works without an internet connection
  • Starts instantly from your home screen or dock

Look for the install icon at the right end of your browser’s address bar, or open the browser menu and choose Install Interformat.