JWT decoder and encoder

Decode a JWT to read its header and claims, or build and HMAC-sign a new one. Nothing leaves your browser.

About jwt decoder and encoder

Paste a token to see its header and payload as colour-coded JSON. Time claims like `exp`, `nbf` and `iat` are also rendered as readable dates and flagged when a token is expired or not yet valid.

Encode mode goes the other way: edit the header and claims as JSON, supply a shared secret, and an HS256, HS384 or HS512 signature is computed locally with Web Crypto.

Frequently asked

Is the signature verified when I decode? No. Decoding only parses the token. A JWT payload is Base64, not encrypted, so never trust an unverified token on the server side.

Is it safe to paste a production token here? The decode runs entirely in your browser and nothing is transmitted. Even so, treat a live token like a password and revoke it if you are unsure.