• 100% Free
  • No Sign-Up
  • No Credit Card
  • No Free Trial
  • No Pro Tier
  • No Watermarks

Nothing is uploaded. Just open it and start.

Decode and verify JSON Web Tokens

Free, no sign-up, no credit card, no trial. Your tokens and keys stay on your machine — paste any JWT to read its header, payload and claims, see exactly when it expires, and verify the signature against your secret or public key.

Header, payload & claims

Pretty-printed header and payload, a labelled claims table, Bearer prefixes and wrapped tokens handled, and JWE recognised.

Live expiry with clock skew

exp, nbf and iat in your time and UTC, a badge that updates every second, and an allowance for clocks that disagree.

Verify, sign & review

Secrets in text, Base64 or hex; PEM, JWK or JWKS by kid; build and sign test tokens; security notes on risky tokens.

100% private, client-side

Tokens, secrets, and keys never leave your browser. There's no server round trip, ever.

Frequently asked questions

Is my token or secret sent to a server?
No. Decoding, claim checks, signing and signature verification all happen in your browser with the built-in Web Crypto API. Tokens, secrets and keys never leave the page and are never saved. The optional token history is off unless you turn it on, keeps only tokens (never a secret or key) in this browser, and is wiped when you turn it off.
What's the difference between decoding and verifying a JWT?
Decoding just Base64URL-decodes the header and payload so you can read them — anyone can do that, since a JWT isn't encrypted. Verifying checks the signature against a secret or public key to prove the token is authentic and hasn't been changed. This tool does both. An encrypted token (JWE, five parts) is recognised as such: only its header can be read without the recipient's key.
Which signing algorithms and keys can it verify?
HMAC (HS256, HS384, HS512) with a shared secret typed as text, Base64, Base64URL or hex; and RSA, RSA-PSS, ECDSA and EdDSA (RS256, PS256, ES256, EdDSA and more) with a PEM public key, an X.509 certificate, a JWK, or a whole JWK set from the issuer's jwks_uri, where the key is picked by the token's kid.
Can I paste a token straight from an Authorization header?
Yes. "Bearer ", "Authorization: Bearer", quotes, token= and line breaks are removed for you, and the page says what it tidied up.
How do I check whether a JWT is expired?
Paste the token: exp, nbf and iat are shown in your own time and in UTC with how long ago or ahead they are, and an Active, Expired or Not valid yet badge that updates every second. A clock-skew allowance (none, 30 s, 1 min or 5 min) covers servers whose clocks differ a little, and each time links to the Unix Timestamp Converter.
Why does verification fail even though the token looks correct?
The page says which case it is: a wrong secret (or a secret the server keeps as Base64 or hex bytes), a private key pasted where the public key goes, a key of the wrong type for the algorithm, a key set without the token's kid, or a critical header extension a verifier has to refuse. Only the signature is checked here, so an expired but authentic token still verifies — expiry is shown separately.
Can I create a test token?
Yes. Build & sign lets you edit the header and payload and sign with a secret, a pasted private key, or a key pair made in your browser, or build an unsigned alg: none token to check that your server refuses it. Open in decoder carries the token and its secret or public key across, so it verifies straight away.
What do the security notes check?
alg none, a missing expiry or a very long lifetime, personal data in the payload, a well-known or too-short HMAC secret, and risky headers: jku and x5u (keys from a URL), an embedded jwk or x5c, and a kid with path or injection characters. They are hints for a review, not a verdict.
Is the JWT Decoder really free?
Yes. No sign-up, no payment details, no expiry, and no locked features. Decode, verify and sign as many tokens as you like.

Spotted a bug or have a suggestion?

Found something broken, have an idea, or just want to say thanks about any of our tools? Every message reaches a real person.