Skip to content

JWT Debugger

Decode a JSON Web Token's header and payload, read its timestamps, and verify HMAC signatures against a secret.

JWT Debugger

Decode and inspect your JSON Web Tokens.

HEADER: ALGORITHM & TOKEN TYPE
Waiting for token...
PAYLOAD: DATA
...
VERIFY SIGNATURE
Verification runs in your browser with the Web Crypto API; the secret is never sent anywhere. Even so, do not paste production secrets here.

What JWT Debugger does

A JWT is three base64url segments separated by dots: a header naming the algorithm, a payload of claims, and a signature. The first two are encoded, not encrypted, so anyone holding the token can read them.

Decoding shows you what a token actually contains, which is usually the fastest way to explain an unexpected authorisation failure: an expired token, the wrong audience, or a claim that never made it in.

  • Decode the header and payload of any well-formed token
  • Render exp, iat and nbf as readable dates and flag an expired token
  • Verify HS256, HS384 and HS512 signatures against a secret you supply
  • Copy either decoded section

How to use JWT Debugger

  1. 1

    Paste the token

    Paste the token itself, without the Bearer prefix used in an Authorization header.

  2. 2

    Read the claims

    The payload shows the claims. Timestamps are converted to readable dates, with expiry called out.

  3. 3

    Verify the signature if you need to

    Supply the shared secret to check an HMAC-signed token. Verification runs in the page.

Example

The three parts of a token

Input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0Iiwibm9uY2UiOjF9.dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk

Output

Header:  { "alg": "HS256", "typ": "JWT" }
Payload: { "sub": "1234", "nonce": 1 }
Signature: verified only with the secret

The header and payload are base64url text, not ciphertext. Never put anything confidential in a JWT payload.

Limits and known behaviour

  • Only HMAC algorithms can be verified here, because they use a single shared secret. RS256, ES256 and other asymmetric algorithms need the issuer's public key and are decoded but not verified.
  • Decoding a token proves nothing about its validity. A token can decode perfectly and still be expired, revoked, or signed by the wrong party.
  • The tool does not check the issuer, audience, revocation status or key rotation; those are decisions for your application.
  • Do not paste production secrets anywhere you have not verified. This page runs verification locally, but that is a habit worth keeping generally.

Privacy and data handling

Runs entirely in your browser

  • Decoding and signature verification both happen in this page. Neither the token nor the secret is transmitted.
  • Nothing is stored; reloading clears the fields.

Site-wide data handling, including analytics and advertising, is described in the privacy policy.

Frequently asked questions

Is the payload encrypted?

No. It is base64url encoded, which is reversible by anyone. Treat everything in a JWT payload as public and never place personal data or secrets in one.

My token decodes fine, so why is my API rejecting it?

Check exp first, then compare iss and aud against what the API expects, then confirm the signing key. A token that decodes is not a token that validates.

Why can it not verify my RS256 token?

RS256 is signed with a private key and verified with the corresponding public key, usually fetched from the issuer's JWKS endpoint. There is no shared secret to type in.