JWT Decoder & Encoder

Decode a JSON Web Token, check its expiry, verify an HMAC signature, or sign a new token.

Tokens and secrets stay in your browser. Still, avoid pasting live production tokens into any website.

Header
Payload

Signature valid

Signature does not match

Only HMAC (HS) signatures can be checked with a secret. RS and ES tokens need the public key.

Signed token

            
        

JWT Decoder & Encoder

A JSON Web Token (JWT) is three Base64URL parts: a header, a payload of claims, and a signature. Paste a token to read the header and payload, with timestamps such as iat and exp shown as dates and a clear warning if it has expired. With the secret you can verify HS256, HS384 and HS512 signatures, or build and sign a new token for testing. Everything runs in your browser with the Web Crypto API.

How to use JWT Decoder & Encoder

  1. Paste the token.
  2. Read the decoded header and payload and the expiry status.
  3. To verify an HMAC-signed token, enter the secret.
  4. To create a token, edit the header, payload and secret on the encoder side and copy the signed token.

When it comes in handy

  • Debugging login and API authentication problems.
  • Checking which claims and expiry a token carries.
  • Generating test tokens for development.

Frequently asked questions

Is a JWT encrypted?
No. A signed JWT is only encoded, so anyone with the token can read the payload. Never put passwords or secrets in it.
Can it verify RS256 tokens?
Not at the moment. RS256 and ES256 tokens are decoded, but verifying them needs the issuer's public key; check them in your backend library.
Should I paste production tokens here?
The token stays in your browser, but a live token is a credential. Prefer expired or test tokens on any website.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.