What is a JWT?
A JSON Web Token is a compact, URL-safe token made of three Base64URL parts separated by dots: header (algorithm and type), payload (claims such as sub, exp, iat) and signature. JWTs are widely used for API authentication and single sign-on.
What this tool does
- Decode any token and pretty-print its header and payload.
- Show time claims (
iat,nbf,exp) as readable dates and tell you whether the token is expired. - Verify the signature with a shared secret (HS256/384/512) or a public key in PEM or JWK format (RS*, PS*, ES*).
- Sign new tokens for testing, from your own header, payload and key.
Security notes
- Decoding does not prove a token is genuine; only signature verification does.
- Tokens with
alg: "none"are unsigned and should always be rejected by servers. - Your tokens, claims and keys are processed with the browser’s Web Crypto API and are never sent anywhere or saved, even when “Remember tool inputs” is on.