What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token used mainly for authentication and information exchange. It has three Base64url-encoded parts separated by dots: header.payload.signature. The header describes the token type and signing algorithm; the payload carries claims like user ID, roles, and expiry; the signature lets a server verify the token wasn't tampered with.
Is decoding the same as verifying?
No — decoding just reads what a token claims; verifying checks whether it's genuine. The header and payload are only Base64url-encoded, not encrypted, so anyone can decode and read them without a key, which is why this tool shows them immediately. Verifying means checking the signature against the issuer's secret (for HMAC algorithms) or public key (for RSA/ECDSA), which proves the token wasn't altered after it was signed. Paste a secret or public key below and this tool verifies it too — using your browser's native Web Crypto API, so the key never leaves your device.
Frequently asked questions
Why shouldn't I trust a decoded JWT without verifying it?
Anyone can craft a JWT with any payload they want — decoding just reveals what's claimed, not whether it's genuine. A server must always verify the signature before trusting the claims inside.
What does the "exp" claim mean?
exp is a standard claim holding the token's expiry as a Unix timestamp (seconds since 1970-01-01). Past that time, a correctly-implemented server should reject the token even if the signature is valid.
Is my token, secret, or key uploaded when I use this tool?
No. Decoding and signature verification both happen instantly in your browser — decoding uses built-in JavaScript functions, and verification uses the Web Crypto API (the same cryptography engine built into every modern browser). Nothing you paste here — the token, a secret, or a public key — is ever sent to a server. Still, treat real tokens and secrets as sensitive and avoid pasting production credentials into any third-party tool, including this one.
Which signing algorithms can this tool verify?
HMAC (HS256/384/512) with a shared secret, RSA (RS256/384/512 and PS256/384/512) with the issuer's public key, and ECDSA (ES256/384/512) with the issuer's public key. Public keys must be in PEM/SPKI format — the block that starts with -----BEGIN PUBLIC KEY-----.
The token's alg is "none" — what does that mean?
It means the token was never cryptographically signed at all — anyone could construct one with any payload they like. A small number of real-world JWT libraries have shipped vulnerabilities that let an attacker change alg to "none" and bypass verification entirely, so a server that accepts this algorithm is trusting an unsigned token. This tool flags it explicitly rather than silently treating it as valid.