JWT Encoder & Decoder

Decode any JWT and inspect its header, payload, and signature. Encode new tokens with HS256, RS256, and more.

PayloadExpires in 2280826h
sub
1234567890
name
Jane Doe
iat
1700000000 — Tue, 14 Nov 2023 22:13:20 GMT
exp
9999999999 — Sat, 20 Nov 2286 17:46:39 GMT

01 — Overview

How the JWT Encoder & Decoder works

Paste a JWT to see its three parts broken out with claim explanations and expiry status, or build a new token by filling in the header and payload. Supports HS256, HS384, HS512, RS256, RS384, and RS512. Runs entirely in your browser — nothing is sent to a server.

02 — Use cases

When to use the JWT Encoder & Decoder

  1. 01

    Debug a 401 by inspecting the token your client is sending

  2. 02

    Verify that 'exp' is set correctly before shipping a login flow

  3. 03

    Generate a test token with a known secret for local development

  4. 04

    Quickly check whether a payload contains the claims you expect

03 — Examples

JWT Encoder & Decoder examples

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.signature

ex 01

{ alg: HS256, sub: 1234567890, name: Jane Doe, iat: 1700000000 }

Decoded header and payload. The signature is shown but not verified without a secret.

Build a token with sub=alex, exp=+1h, secret=supersecret

ex 02

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

Signed with HS256 using the provided secret.

Decode a token with an expired exp claim

ex 03

{ sub: "u_8823", exp: 1735689600 } — expired 2 January 2025

The decoder resolves exp to a readable date and flags the token as expired.

Verify HS256 signature with secret "supersecret"

ex 04

Signature valid · alg HS256 · payload unmodified

Supplying the secret turns decoding into verification — without it the signature is shown but unchecked.

04 — FAQ

JWT — frequently asked questions

Is it safe to paste a JWT here?

All decoding happens in your browser using the jose library — your token never reaches our servers. That said, a JWT can be replayed if it's still valid, so don't paste production tokens into any random site (including this one) without rotating them afterwards.

How is decoding different from verification?

Decoding splits a JWT into its base64url-encoded parts so you can read them. Verification checks the signature against a known key. The decoder shows you both halves — but it only verifies if you provide the matching secret or public key.

What's the difference between HS256 and RS256?

HS256 uses a shared secret (HMAC SHA-256) — same key signs and verifies. RS256 uses an RSA private/public key pair — the private key signs, the public key verifies. Use RS256 when the verifier doesn't need to mint tokens.

Why does my token say 'expired'?

The 'exp' claim is a Unix timestamp. If it's earlier than the current time, the token has expired and most verifiers will reject it. The decoder shows a human-readable expiry next to the claim.

Can I edit a payload and re-sign?

Yes — switch to encode mode, paste the header and payload, set the algorithm, and provide a secret or private key. The tool produces a fresh signed token.

Do you support encrypted JWTs (JWE)?

Not yet. The decoder handles JWS (signed) tokens. JWE support is on the roadmap — let us know if you need it.

05 — Reference

Specs and further reading

The primary sources this tool follows. Where behaviour is defined by a specification, we link the specification rather than a summary of it.

07 — More

Tools that pair with JWT

Last updated .