JWT Decoder
How to Use JWT Decoder
1
Paste Your JWT
Paste the JWT token. The header, payload, and signature are decoded automatically.
2
Inspect Claims
Review the formatted JSON payload and see exp, iat, and nbf converted to readable dates with expiry status.
3
Verify Signature (Optional)
Enter your secret and choose the algorithm to verify an HS256/HS384/HS512 HMAC signature.
Key Features
Instant Header & Payload Decoding
Header and payload are base64-decoded and pretty-printed the moment you paste a token.
Expiry & Date Interpretation
exp, iat, and nbf claims are shown as readable dates with a live valid / expired status.
HMAC Signature Verification
Verify HS256, HS384, and HS512 signatures using the Web Crypto API and your secret.
One-Click Copy
Copy the raw header or payload JSON instantly for debugging.
100% Client-Side
Tokens are decoded locally — your JWT secrets never leave your browser.
Frequently Asked Questions about JWT Decoder
Yes. The header and payload are simply base64-encoded JSON and contain no secrets. Verification also runs locally with Web Crypto.