How to use
- Paste your JWT into Encoded token.
- Set View to Claims to inspect claim values, dates and descriptions.
- Set Time zone for dates to Local or UTC.
- Open Verify signature and paste your shared secret or public key.
- For HS256/384/512, set Secret encoding to match your secret: UTF-8 text, Base64URL, Base64 or Hex.
Examples
Verify an HS256 token with a demo secret
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwLCJleHAiOjE3MDAwMDM2MDB9.RLuNxTd4dLt2uJyNF3-asZ6S5bcvMhQCmlrokunrONI
Header: {"alg":"HS256","typ":"JWT"}
Payload: {"sub":"1234567890","name":"Jane Doe","iat":1700000000,"exp":1700003600}
Expired · Signature verifiedCheck a Bearer token with the wrong secret
Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwLCJleHAiOjE3MDAwMDM2MDB9.RLuNxTd4dLt2uJyNF3-asZ6S5bcvMhQCmlrokunrONI
Header: {"alg":"HS256","typ":"JWT"}
Payload: {"sub":"1234567890","name":"Jane Doe","iat":1700000000,"exp":1700003600}
Expired · Invalid signatureTimestamps in exp, iat and nbf are Unix time — convert them with the Unix Timestamp Converter.
FAQ
Is it safe to paste my JWT here?
Decoding and verification run in your browser; the tool does not upload or save your token or key. The page uses Google Analytics for tool events, but those events contain only the tool slug, not your token, claims or key. Treat production tokens like passwords.
Does decoding a JWT mean it's valid?
A readable header and payload do not prove authenticity. Signature verification checks the signature with the supplied key; expiration is shown separately.
Why does my JWT show as expired?
The token is expired when exp is at or before your device's current time. The check allows no clock-skew leeway, so make sure your device clock is correct.
Which JWT algorithms can I verify?
The tool supports HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512 and EdDSA/Ed25519 where your browser supports it. Verification requires HTTPS, and the algorithm comes from the token header rather than a setting you can change.
Can I decode an encrypted JWT?
For a five-part JWE token, only the header is shown. This tool cannot decrypt the payload and does not accept private keys.