decode / verify / sign

JWT Decoder & Verifier

Paste a token to see its header, payload and every claim explained — then check its signature with a secret, PEM or JWK, or sign a new one. Decoding and cryptography run in your browser.

Header & payload, colour-coded
Expiry, not-before & issued-at countdowns
Verify HS, RS, PS & ES signatures
Secrets, PEM, JWK & JWKS keys
Sign tokens from editable JSON

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Header
{
  "alg": "HS256",
  "typ": "JWT"
}
Payload
{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}
Claims
  • subinfo
    1234567890Subject — Subject: 1234567890
  • nameinfo
    John DoeCustom claim
  • iatinfo
    1516239022Issued at — Issued 8 years ago (2018-01-18T01:30:22.000Z)

Signature: 32 bytes — decoding never checks it. Use the Verify tab with the key.