JWT Debugger
Paste a JSON Web Token to see its header and claims in plain language — who issued it, who it’s for, when it expires — and check its signature with a secret, PEM key, certificate or JWKS.
At a glance
- Decodes the header and payload of any JWT, explains standard and common claims (iss, sub, aud, exp, nbf, iat, scope, roles …) and shows times in UTC and your local time.
- Shows whether the token is expired, not yet valid or still valid, with a live countdown.
- Verifies the signature for HS256/384/512, RS256/384/512, PS256/384/512, ES256/384/512 and EdDSA (Ed25519) using your browser’s Web Crypto.
- Accepts keys as a shared secret (text, Base64, Base64URL or hex), PEM public or private keys, PKCS#1, X.509 certificates, a JWK or a whole JWKS, picking the key by kid.
- Warns about real security problems: alg “none”, keys or key URLs supplied by the token itself (jwk, jku, x5u), missing expiry, weak or well-known secrets and secrets placed in the payload.
- Runs entirely in your browser — tokens and keys are never uploaded or logged — and also decodes the header of encrypted JWE tokens.
Step by step
How to decode and verify a JWT
- 1
Paste the token
Paste the JWT — a “Bearer …” header value works too. The header, payload and claims appear instantly.
- 2
Check the claims
Read who issued the token, who it’s for and when it expires; warnings appear above the claims.
- 3
Add the key
Enter the secret for HS256, or paste the public key, certificate or JWKS for RS256, ES256 and EdDSA.
- 4
Read the result
“Signature verified” means the token is authentic and unchanged; otherwise check the key or the token.
Features
Everything you need, nothing you don’t
Claims in plain English
Every claim labelled — issuer, audience, scopes, roles — with dates converted and the time left until expiry.
Real signature check
Verifies with Web Crypto, the same cryptography your browser uses for HTTPS, for every common JWS algorithm.
Any key format
Secrets, PEM, PKCS#1, certificates, JWK or a JWKS from your identity provider — no conversion needed.
Security warnings
Flags unsigned tokens, embedded keys, long lifetimes and weak secrets before they cause trouble.
Private by design
Nothing leaves your device, so production tokens are safe to inspect.
Build tokens too
Switch to Encode & sign to create a test token, then verify it here in one click.
Anatomy of a JWT
| Part | Contains | Example |
|---|---|---|
| Header | The signing algorithm and token type, Base64URL-encoded JSON | {"alg":"RS256","typ":"JWT","kid":"key-1"} |
| Payload | The claims: who the token is about, for whom, and how long it lasts | {"sub":"42","aud":"api","exp":1767229200} |
| Signature | Proof that header and payload came from the key holder unchanged | Base64URL bytes of an HMAC, RSA, ECDSA or EdDSA signature |
Decoding is not verifying
Anyone can decode a JWT — the header and payload are only Base64URL-encoded, not encrypted. That is why tokens must never carry passwords or other secrets. Verifying checks the signature with the right key, which proves who created the token and that nobody changed a single character.
A server should verify the signature, then check exp, nbf, iss and aud, and accept only the algorithms it expects. Never trust the alg value or a key that arrives inside the token itself. Public keys for providers such as Auth0, Okta, Microsoft Entra ID, Cognito and Firebase are published at a JWKS URL, usually ending in /.well-known/jwks.json.
FAQ
Frequently asked questions
Is it safe to paste a production token here?
Why does it say “Invalid signature”?
Where do I find the public key to verify RS256 tokens?
Can it decrypt JWE tokens?
Why are exp and iat such large numbers?
Keep going
Related tools
JWT Encoder
Create and sign JWTs in your browser with HS256, RS256, PS256, ES256 or EdDSA: edit claims, set expiry, generate keys and a JWKS. Keys never leave your device.
Base64 Encoder & Decoder
Encode text or files to Base64 and decode Base64 back — UTF-8, URL-safe Base64URL, data URLs for images, file type detection. Free, private, no upload.
JSON Formatter & Validator
Format, validate, minify and repair JSON online. Get the exact line and column of every error, a collapsible tree view and sorted keys — private, in-browser.
Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-512, SHA-3, BLAKE3, CRC32 and HMAC hashes of text or files, and verify checksums. Free, fast and private — no upload.
XML to JSON Converter
Convert XML to JSON and JSON to XML online. Keeps attributes, arrays and leading zeros intact, shows exact error lines and never uploads your data.
DNS Lookup
Free DNS lookup: check A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records of any domain, see SPF and DMARC, and do reverse DNS for an IP address.
Last updated Report a problem or suggest a feature