Professional JWT tool for developers: decode, generate, verify, and compare JSON Web Tokens. Supports HS256, RS256, and ES256 signature verification with secret/public keys. Create new signed JWTs from custom header and payload JSON. Compare two tokens side-by-side with visual diff highlighting added, removed, and changed claims. Save up to 10 tokens with custom labels for quick access. JWTs are used extensively in modern authentication systems, APIs, microservices, and SPAs for secure, stateless authentication. This comprehensive tool helps you debug authentication issues, verify token authenticity, generate test tokens, compare environments, and inspect claims with automatic explanations. Features visual expiration badges (green/yellow/red), base64 raw view toggle, auto-decode as you type, and timestamp conversion. All processing happens completely securely in your browser using Web Crypto API—tokens never leave your computer. Perfect for developers, DevOps engineers, and security professionals working with JWT-based authentication.
JSON Web Tokens (JWTs) are a standard for securely transmitting information as JSON objects in authentication systems, APIs, and microservices architectures. This tool provides a fast, secure way to decode and inspect JWTs by extracting and displaying the header, payload, and signature information. JWTs are stateless, URL-safe, and work seamlessly across domains, making them ideal for modern web applications, mobile apps, and APIs. Whether you're debugging authentication issues, verifying user claims, checking token expiration, or understanding API authentication flows, this decoder simplifies JWT inspection with an instant, privacy-first approach.
Method 1: Decode Your JWT
Method 2: Inspect Individual Token Parts
Method 3: Save and Manage Token History
Method 4: Verify Token Signature (HS256)
Method 5: Learn with Sample Token
Keyboard Shortcuts (Power Users)
Pro tip: This tool auto-decodes as you type or paste, so you can instantly see token contents without clicking any buttons. Save frequently-used tokens with custom labels for even faster debugging!
Debugging Authentication and Authorization Issues
When users report authentication problems or receive "unauthorized" errors, extract their JWT and decode it using this tool to verify the token contents, check expiration status, and confirm claims (sub for user ID, roles for authorization). Often you'll discover tokens are expired, missing required claims, or contain incorrect values—information that's impossible to see without decoding. This tool instantly reveals the underlying issue without needing server logs.
Verifying User Claims in SPA Applications
Single-page applications (SPAs) that store JWTs in localStorage or sessionStorage often need to inspect what user data is stored in the token. Decode the JWT to verify the user ID, email, roles, permissions, and other claims are correctly set. This is essential when debugging authorization issues where a user claims they should have certain permissions but the token doesn't contain the expected claims.
Inspecting API Response Tokens
When testing APIs that return JWTs in responses (especially OAuth2 or OpenID Connect flows), paste the returned token here to instantly see what the API included in the token. Verify that all expected claims are present, user information is correct, and the token hasn't expired. This speeds up API development and testing significantly compared to manually decoding tokens on the server.
Understanding JWT Structure for Development and Learning
New developers learning about JWT authentication can use this tool to understand the three-part structure (Header.Payload.Signature), see real token examples, and learn what information JWTs typically contain. The sample token feature provides a hands-on way to explore JWTs without requiring access to a live authentication system.
Q: Does this tool verify JWT signatures?
A: Yes! This tool now supports HS256 signature verification. You can verify JWT signatures signed with HMAC-SHA256 by entering your secret key in the Verify Signature section. The tool will validate whether the signature is authentic and the token hasn't been tampered with. Important: Only use test or development keys—never enter production secret keys in browser tools. For production tokens, always verify signatures on your secure server. Note: This tool currently supports HS256 only; RS256 and ES256 support may be added in future updates.
Q: How do I check if a JWT is expired?
A: JWTs contain an 'exp' claim that specifies the expiration time as a Unix timestamp (seconds since epoch). This tool automatically checks the expiration time and displays whether the token is valid or expired. Simply decode the JWT using this tool and look for the expiration status in the payload output. If the current time is greater than the exp value, the token is expired. Your server must also validate expiration before accepting the token.
Q: What are JWT claims and which ones matter?
A: JWT claims are pieces of information stored in the payload (the middle part of a JWT). Standard claims include: sub (subject/user ID), iss (issuer), aud (audience), exp (expiration time), iat (issued at time), nbf (not before time), and jti (unique identifier). Custom claims specific to your application can also be included. When debugging tokens, check the 'exp' and 'sub' claims first to verify the token isn't expired and belongs to the correct user.
Q: Can I modify or create a JWT with this tool?
A: No, this tool only decodes JWTs. You cannot modify or create new tokens here. To create or modify JWTs, use backend code or specialized JWT tools that handle signing. Any JWT created without the proper signature will be rejected by your server. If you decode a JWT and want to see how changes would affect it, modify the payload values conceptually and re-encode manually, but understand this wouldn't be a valid token without proper signing.
Q: When and why should I use JWTs for authentication?
A: JWTs are ideal for stateless authentication in modern web and mobile applications, APIs, and microservices. They contain all user information in the token itself, eliminating the need for server-side session storage. JWTs are URL-safe, can be easily transmitted in headers, and work well with CORS and cross-domain requests. However, JWTs require HTTPS to prevent interception, proper signature verification on the server, and careful management of sensitive information in the payload (don't include passwords or secrets).
Q: What are the three parts of a JWT and what do they mean?
A: A JWT has three parts separated by dots: Header (specifies token type and signing algorithm), Payload (contains the actual data/claims including user info and expiration), and Signature (cryptographically proves the token hasn't been tampered with). The header and payload are Base64-encoded and human-readable. The signature can only be verified with the secret key. This tool decodes and displays all three parts so you can inspect the data and signature value.
Q: What is the token history feature and how does it help?
A: Token history is a unique feature that lets you save up to 10 JWT tokens with custom labels for quick access during debugging. For example, you can save tokens labeled "Production API", "Staging Server", "Test User 1", etc. This eliminates the need to constantly re-paste tokens when switching between different environments or test accounts. Simply select a saved token from the dropdown to instantly load and decode it. This feature is stored locally in your browser and never sent to any server, maintaining complete privacy.
JWTs are not encrypted by default—they are only Base64-encoded and signed. Anyone can decode a JWT to see its contents, which is why sensitive information like passwords should never be stored in JWT claims. The signature proves the token came from a trusted source and hasn't been modified, but only if verified with the correct signing key. Always use HTTPS when transmitting JWTs to prevent interception, and always verify signatures on your server before trusting the token's claims.