📅 Tax Season 2026 58 days remaining  📁 Collect W-2s, 1099s & receipts first.
🛡️ Security Tool

JWT Decoder

Decode, inspect and verify JSON Web Tokens instantly.

🔒 100% client-side — your token never leaves your browser
🔑 Paste your JWT
🔐

Paste a JWT above — header, payload and claims are decoded instantly as you type.

JWT Algorithm Reference

AlgorithmFamilyTypeKeyUse Case
HS256HMAC-SHA256SymmetricShared secretSingle-server apps, APIs
HS384HMAC-SHA384SymmetricShared secretHigher-security HMAC
HS512HMAC-SHA512SymmetricShared secretMaximum HMAC security
RS256RSA-SHA256AsymmetricRSA key pairOAuth2, OIDC, microservices
RS384RSA-SHA384AsymmetricRSA key pairHigher-security RSA
RS512RSA-SHA512AsymmetricRSA key pairMaximum RSA security
ES256ECDSA P-256AsymmetricEC key pairMobile, IoT, compact tokens
ES384ECDSA P-384AsymmetricEC key pairHigh-security EC
ES512ECDSA P-521AsymmetricEC key pairMaximum EC security
PS256RSASSA-PSSAsymmetricRSA key pairFIPS-compliant systems
noneNone⚠️ Unsecured — dev only

Features

Instant Decode

Header and payload decoded as you type — no button click needed.

🔒
100% Client-Side

Your token is decoded in the browser and never sent to any server.

⏱️
Expiry Detection

Automatically detects and highlights expired, active and not-yet-valid tokens.

🔐
Signature Verify

Verify HS256/384/512 signatures with your secret key, right in the browser.

🎨
Colour-Coded Parts

Header, payload and signature highlighted in different colours for clarity.

🆓
100% Free

No account, no limits, no watermarks — free forever.

Frequently Asked Questions

Is it safe to paste my JWT here?
Yes. This tool decodes entirely in your browser using JavaScript. Your token is never sent to any server — you can verify this by opening the browser's Network tab while using the tool. However, you should still avoid sharing JWTs in screenshots or with untrusted parties, as they can grant access to protected resources.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe format for representing claims between parties. It has three Base64URL-encoded parts separated by dots: a header (algorithm & type), a payload (claims/data), and a signature (integrity proof). JWTs are widely used for authentication and authorisation in APIs and web apps.
Can this tool verify the signature?
For HS256, HS384 and HS512 tokens you can enter your secret key and the tool will verify the signature client-side using the Web Crypto API. For RS256/ES256 (asymmetric) tokens the tool shows the signature bytes but cannot verify without the public key in PEM format — paste the PEM key and it will attempt verification.
What do exp, iat and nbf mean?
These are registered JWT claim names. exp (Expiration Time) is the Unix timestamp after which the token must be rejected. iat (Issued At) is when the token was created. nbf (Not Before) is the earliest time the token should be accepted. The tool automatically converts these Unix timestamps to human-readable dates.
What is the difference between HS256 and RS256?
HS256 uses a single shared secret for both signing and verifying (symmetric). RS256 uses a private key to sign and a separate public key to verify (asymmetric). RS256 is preferred in distributed systems where the verifier should be able to check tokens but not create new ones — for example, multiple microservices trusting an auth server.
Why is "alg: none" dangerous?
If a server accepts tokens with "alg: none" it means no signature is required, allowing an attacker to forge any token by simply crafting the header and payload without signing. Always reject tokens with alg: none in production.
All Tools
Homework Planner
GPA Calc
Flashcards
Citations
Study Timer
Grade Calc
Unit Conv.
File Compress
File Convert
PDF Merger
Image→PDF
Text Extract
Video DL
PDF Splitter
File Encrypt
BG Remover
FG Remover
Color Changer
Img Resizer
QR Code
Percentage
Loan EMI
Mortgage
Tax Calc
Salary
Currency
BMI
Tip Calc
Compound Int.
Translator
Summarizer
Transcription
AI Chat
Project Maker
Paraphraser
Word Counter
Case Converter
Paraphraser
Summarizer
Text Extractor
Find & Replace
Diff Checker
Text to Speech
Lorem Ipsum
JSON Format
Base64
Regex Tester
Speed Test
My IP
Notes App
Stock Advisor
Risk Simulator
CSV↔JSON
XML↔JSON
Base64
URL Encode
Binary↔Text
MoleMath
ChemScope
Periodic Table
SEO Analyzer
Speed Test
Keywords
Internal Links
Cannibalization
Tech Stack
Islam Home
Prayer Times
Quran Reader
Halal/Haram
Christianity
All Religions
Prayer Times
Athan
Qibla
Tasbih
Halal Scanner
Zakat Calc
Masjid Finder
Ramadan
Quran Reader
Hadith
Flappy Bird
Snake
Chess
2048
Tetris
All Games →
All News
Tech News
AI News
World News
Islamic News
Finance News
Sports
Science
Health
Web Dev
Tax Services
Business
Book Appt
Expenses
All Services