Decode a JSON Web Token to read its header and payload, verify the signature with a secret, PEM key, certificate or JWKS, or create and sign a new JWT. Supports HS, RS, PS and ES algorithms (256/384/512) and shows iat, nbf and exp as dates. Tokens and keys are processed in your browser.
A JSON Web Token (JWT, RFC 7519) is a compact, URL-safe string used to pass claims such as a user ID or permissions between systems, typically as an Authorization: Bearer header or an OpenID Connect ID token. It has three Base64URL-encoded parts separated by dots: a header (algorithm and token type), a payload (the claims) and a signature that proves the token was issued by someone holding the key and has not been modified.
This tool decodes tokens, checks their signatures, and generates signed tokens for testing.
kid) and Payload JSON.iat (Issued At), nbf (Not Before) and exp (Expires At) shown as local dates, with expired and not-yet-valid tokens flaggedPUBLIC KEY, RSA PUBLIC KEY, X.509 CERTIFICATE, JWK or JWKS (the key matching the token's kid is used, otherwise the first key)PRIVATE KEY (PKCS#8), RSA PRIVATE KEY (PKCS#1), EC PRIVATE KEY (SEC1) or JWK| Algorithm | Type | Key for signing / verifying |
|---|---|---|
| HS256, HS384, HS512 | HMAC with SHA-2 | One shared secret for both |
| RS256, RS384, RS512 | RSASSA-PKCS1-v1_5 | RSA private key / public key |
| PS256, PS384, PS512 | RSASSA-PSS | RSA private key / public key |
| ES256, ES384, ES512 | ECDSA (P-256, P-384, P-521) | EC private key / public key |
| none | Unsigned | No key |
Need a key pair to try RS or ES tokens? Create one with the Public-Key Generator, or a random HMAC secret with the Shared-Key Generator.
Decoding, verification and signing all happen in your browser; tokens and keys are not sent to any server. Note that the token, secret and keys you enter are saved in this browser's storage so they are still there next time. Avoid pasting production secrets on a shared computer.
The key does not match the one used to sign the token, or the token was modified. Common causes: a Base64 secret entered without checking Secret is base64 encoded, a public key from a different key pair, or extra spaces copied with the token.
Only the signature is verified. exp and nbf are displayed and flagged when the token is expired or not yet valid, but claims such as iss and aud are not checked.
No. The tool handles signed tokens (JWS) with the algorithms listed above.