JWT

Decode a JSON Web Token to read its header and payload, verify the signature with a secret, PEM key, certificate or JWKS, or create and sign a new JWT. Supports HS, RS, PS and ES algorithms (256/384/512) and shows iat, nbf and exp as dates. Tokens and keys are processed in your browser.

About this tool

What is a JWT?

A JSON Web Token (JWT, RFC 7519) is a compact, URL-safe string used to pass claims such as a user ID or permissions between systems, typically as an Authorization: Bearer header or an OpenID Connect ID token. It has three Base64URL-encoded parts separated by dots: a header (algorithm and token type), a payload (the claims) and a signature that proves the token was issued by someone holding the key and has not been modified. This tool decodes tokens, checks their signatures, and generates signed tokens for testing.

How to use

Decode and verify a token

  1. Select Decode at the top.
  2. Paste the token into JWT. The header and payload are decoded and shown as formatted JSON, and the algorithm is read from the header.
  3. To verify the signature, enter the Secret (HS256/384/512) or the Public Key to verify (RS, PS and ES algorithms).
  4. The result is shown as Signature Verified, Invalid Signature, or Not Verified when no key is given.

Generate a token

  1. Select Encode.
  2. Choose the Algorithm and edit the Header (for example to add a kid) and Payload JSON.
  3. Enter the Secret or the Private Key to sign.
  4. The signed token appears in JWT - Generated as you type. Copy it with the button in the editor.

Features

  • Decodes header and payload independently, so one broken part does not hide the other
  • Color-coded token: header, payload and signature are highlighted separately
  • iat (Issued At), nbf (Not Before) and exp (Expires At) shown as local dates, with expired and not-yet-valid tokens flagged
  • HMAC secrets as plain text or Base64 (Secret is base64 encoded)
  • Public keys for verification: PEM PUBLIC KEY, RSA PUBLIC KEY, X.509 CERTIFICATE, JWK or JWKS (the key matching the token's kid is used, otherwise the first key)
  • Private keys for signing: PEM PRIVATE KEY (PKCS#8), RSA PRIVATE KEY (PKCS#1), EC PRIVATE KEY (SEC1) or JWK
  • Signing and verification use the browser's Web Crypto API

Supported algorithms

AlgorithmTypeKey for signing / verifying
HS256, HS384, HS512HMAC with SHA-2One shared secret for both
RS256, RS384, RS512RSASSA-PKCS1-v1_5RSA private key / public key
PS256, PS384, PS512RSASSA-PSSRSA private key / public key
ES256, ES384, ES512ECDSA (P-256, P-384, P-521)EC private key / public key
noneUnsignedNo key

Need a key pair to try RS or ES tokens? Create one with the Public-Key Generator, or a random HMAC secret with the Shared-Key Generator.

FAQ

Is it safe to paste a real token here?

Decoding, verification and signing all happen in your browser; tokens and keys are not sent to any server. Note that the token, secret and keys you enter are saved in this browser's storage so they are still there next time. Avoid pasting production secrets on a shared computer.

Why does it say "Invalid Signature"?

The key does not match the one used to sign the token, or the token was modified. Common causes: a Base64 secret entered without checking Secret is base64 encoded, a public key from a different key pair, or extra spaces copied with the token.

Does verification check expiry, issuer or audience?

Only the signature is verified. exp and nbf are displayed and flagged when the token is expired or not yet valid, but claims such as iss and aud are not checked.

Are encrypted tokens (JWE) or EdDSA supported?

No. The tool handles signed tokens (JWS) with the algorithms listed above.