JWT Encoder & Decoder
Decode any JWT and inspect its header, payload, and signature. Encode new tokens with HS256, RS256, and more.
- sub
- 1234567890
- name
- Jane Doe
- iat
- 1700000000 — Tue, 14 Nov 2023 22:13:20 GMT
- exp
- 9999999999 — Sat, 20 Nov 2286 17:46:39 GMT
01 — Overview
How the JWT Encoder & Decoder works
Paste a JWT to see its three parts broken out with claim explanations and expiry status, or build a new token by filling in the header and payload. Supports HS256, HS384, HS512, RS256, RS384, and RS512. Runs entirely in your browser — nothing is sent to a server.
02 — Use cases
When to use the JWT Encoder & Decoder
- 01
Debug a 401 by inspecting the token your client is sending
- 02
Verify that 'exp' is set correctly before shipping a login flow
- 03
Generate a test token with a known secret for local development
- 04
Quickly check whether a payload contains the claims you expect
03 — Examples
JWT Encoder & Decoder examples
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.signature
ex 01{ alg: HS256, sub: 1234567890, name: Jane Doe, iat: 1700000000 }
Decoded header and payload. The signature is shown but not verified without a secret.
Build a token with sub=alex, exp=+1h, secret=supersecret
ex 02eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
Signed with HS256 using the provided secret.
Decode a token with an expired exp claim
ex 03{ sub: "u_8823", exp: 1735689600 } — expired 2 January 2025
The decoder resolves exp to a readable date and flags the token as expired.
Verify HS256 signature with secret "supersecret"
ex 04Signature valid · alg HS256 · payload unmodified
Supplying the secret turns decoding into verification — without it the signature is shown but unchecked.
04 — FAQ
JWT — frequently asked questions
Is it safe to paste a JWT here?
How is decoding different from verification?
What's the difference between HS256 and RS256?
Why does my token say 'expired'?
Can I edit a payload and re-sign?
Do you support encrypted JWTs (JWE)?
05 — Reference
Specs and further reading
The primary sources this tool follows. Where behaviour is defined by a specification, we link the specification rather than a summary of it.
- RFC 7519: JSON Web Token
IETF — Defines the JWT format and the registered claims including exp, iat, sub, and aud.
- RFC 7515: JSON Web Signature
IETF — Defines the signing structure behind the three-part token this tool decodes.
- RFC 7518: JSON Web Algorithms
IETF — The algorithm registry covering HS256, RS256, and the rest of the alg values.
- JSON Web Token Cheat Sheet
OWASP — Common JWT vulnerabilities, including algorithm confusion and missing expiry validation.
07 — More
Tools that pair with JWT
API Key Generator
Strong API keys and secrets with prefix support — sk_test_, pk_live_, or your own. Configurable length and charset, bulk mode.
Hash Generator
Hash a string with MD5, SHA-1, SHA-256, SHA-512, or bcrypt. Compare two hashes side by side.
UUID Generator
Generate UUIDs (v1, v4, v7, v8) in bulk, with format options and a validator. Cryptographically random by default.