Skip to content
AnyToolBox

Search tools

Find a tool by name or keyword

JWT Decoder

Decode JSON Web Tokens to read the header and payload, check expiry, and verify HMAC signatures.

100% Client-Side

Paste a JWT to see its header, payload and timing claims; add the secret to verify an HMAC signature.

How to use the JWT Decoder

  1. 1

    Paste a JSON Web Token (the three dot-separated parts) into the token box.

  2. 2

    Read the decoded header and payload, formatted as JSON.

  3. 3

    Check the timing claims — issued at, not before and expires — shown as readable dates with a valid/expired status.

  4. 4

    For HS256, HS384 or HS512 tokens, enter the shared secret to verify the signature.

Frequently asked questions

The token is decoded entirely in your browser and is never sent or stored. Still, treat production tokens like passwords: anyone holding a valid token can use it until it expires.

No. The header and payload are only Base64URL-encoded, so anyone can read or forge them. Only a signature check with the right key proves the token wasn't tampered with.

HMAC tokens (HS256, HS384, HS512) can be verified with the shared secret using your browser's Web Crypto API. Tokens signed with public-key algorithms such as RS256 or ES256 are decoded but not verified here.

They are standard timing claims in seconds since 1970: iat is when the token was issued, nbf is when it becomes valid, and exp is when it expires. The tool converts them to your local time and shows how long ago or from now each one is.

No. Encrypted JWE tokens have five parts and need the decryption key. This tool reads standard signed tokens (JWS) with three parts.

Missing a feature or tool?

Tell us what would make JWT Decoder more useful, or what to build next.