JWT Decoder
Read the header and payload of any JWT, see exp and iat times, and verify an HMAC signature. The token never leaves your device.
- Fully offline
Loading…
Features
- Header and payload view
- exp, iat and nbf in local and relative time
- alg none warning
- HS256, HS384 and HS512 verification
- Works offline
Examples
Sample token
- Input
- eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.…
- Output
- { "sub": "1234567890" }
FAQ
Is a JWT encrypted?
No. The header and payload are only Base64URL and anyone can read them; the signature only prevents tampering. Do not put secrets in the payload.
Is my token sent to a server?
No. Decoding and verification run entirely on your device and the secret stays in memory only.