Skip to main content

JSON Web Token (JWT) Debugger

Decode, verify, and generate JSON Web Tokens (RFC 7519) in your browser. Your token and secret never leave this page.

Client-Side Privacy Free Forever Mobile & PC

Paste a JWT below to decode, validate, and verify it. Signing and verification stay in your browser.

Encoded Token

JSON Web Token (JWT)

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTUxNjIzOTAyMn0.KMUFsIDTnFmyG3nMiGM6H9FNFUROf3wh7SmqJp-QV30
Valid JWTSignature Verified

JWT Signature Verification

Optional. Enter the secret used to sign the JWT.

Valid secret

Decoded Header

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Valid header

Decoded Payload

Payload

{
  "sub": "1234567890",
  "name": "John Doe",
  "admin": true,
  "iat": 1516239022
}

Valid payload

What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe format for transmitting claims between parties. A JWT consists of three base64url-encoded parts separated by dots: header.payload.signature. The header describes the algorithm used. The payload contains the claims. The signature is used to verify the token has not been tampered with.

What does this tool do?

Decode a token to read its header and payload, paste the HMAC secret to check the signature, or edit the claims and generate a new signed token. HS256, HS384, and HS512 run with the Web Crypto API in your browser.

Standard JWT claims

  • sub (subject) - the principal that is the subject of the JWT, often a user ID.
  • iss (issuer) - the entity that issued the token.
  • aud (audience) - the intended recipient(s) of the token.
  • exp (expires at) - the Unix timestamp after which the token must not be accepted.
  • iat (issued at) - the Unix timestamp when the token was issued.
  • nbf (not before) - the Unix timestamp before which the token must not be accepted.
  • jti (JWT ID) - a unique identifier for the token.

Decoding vs verification

Decoding reads the header and payload from the base64url encoding. Anyone can decode a JWT - it is not encrypted by default. Verification checks the signature with the shared secret. This debugger verifies HMAC signatures (HS256, HS384, HS512) locally. A matching signature means the payload matches that secret. It does not mean you should trust a production token pasted into a browser.

Privacy and security

  • Decoding and HMAC signing happen in your browser with atob() and Web Crypto.
  • Your token is never transmitted to any server or third party.
  • Do not paste tokens from production systems into any web tool.
  • This tool does not store, log, or persist tokens in any way.

Our Tool Features

Why developers and engineers prefer this tool for everyday development workflows.

Cross-Device Compatibility

Works seamlessly on all modern desktop, tablet, and mobile browsers including Chrome, Firefox, Safari, Edge on Windows, macOS, Linux, Android, and iOS.

Fast In-Browser Execution

Processes your data in real-time directly inside your browser. No queue wait times, no network round-trips, and zero latency.

100% Client-Side Privacy

Your code, tokens, passwords, and files are never transmitted to any external server or saved in logs. Everything runs locally in memory.

Instant File & Clipboard Input

Supports one-click sample loading, file drag-and-drop, and pasting directly from your clipboard (Ctrl + V) for effortless workflows.

Strict Standards Compliant

Built strictly according to official specifications (RFCs, W3C, ISO, and standard cryptographic algorithms) ensuring accurate output every time.

Unlimited Free Usage

No registration, no accounts, no subscriptions, and no hidden daily quotas. Use this tool as many times as you need without restrictions.

Recent Updates & Improvements

Continuously maintained and improved based on developer feedback.

Client-Side Speed & Performance UpgradeRecent Update

Optimized processing algorithms with Web Workers and native browser APIs (SubtleCrypto, Canvas 2D) for instantaneous zero-latency execution.

Clipboard Paste & Drag-and-Drop AddedFeature Added

Added instant clipboard pasting (Ctrl + V) and drag-and-drop file support to accelerate developer productivity without manual downloads.

Enhanced Mobile & Touch Device ExperienceUI/UX Update

Redesigned responsive touch controls, flexible copy buttons, and camera preview framing for mobile and tablet browsers.

Frequently Asked Questions

Related Tools