jibzar

JWT Decoder

Read the header and payload of any JWT, see exp and iat times, and verify an HMAC signature. The token never leaves your device.

  • Fully offline

Loading…

Features

  • Header and payload view
  • exp, iat and nbf in local and relative time
  • alg none warning
  • HS256, HS384 and HS512 verification
  • Works offline

Examples

Sample token

Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.…
Output
{ "sub": "1234567890" }

FAQ

Is a JWT encrypted?

No. The header and payload are only Base64URL and anyone can read them; the signature only prevents tampering. Do not put secrets in the payload.

Is my token sent to a server?

No. Decoding and verification run entirely on your device and the secret stays in memory only.