JWT Decoder
Decode a compact signed JWT locally, inspect its header/payload and interpret time claims. Optionally verify HS256 with your supplied secret or RS256 with an SPKI public key, using browser cryptography.
Your result
How the calculation works
JWT segments use base64url. The signing input is encoded header + "." + encoded payload. Optional verification checks the signature using HMAC SHA-256 or RSA PKCS#1 v1.5 SHA-256. iat, nbf and exp are Unix timestamps.
Worked example
The included demonstration token has a header and payload that can be decoded; its dummy signature is not verified. An exp value at or before the entered current Unix time is labelled expired.
Assumptions and limitations
Decoding does not authenticate a token. A matching signature does not establish issuer, audience, authorization, key trust or full application validity. This supports compact three-part signed tokens, not five-part encrypted JWE. Verification rejects unsupported algorithms and critical extensions.
Use synthetic or non-production tokens when possible. Never provide a private RSA key; RS256 requires a public SPKI PEM key. Token/key data stays in this tab, with no share state or server draft. Reference time defaults to your browser clock on page load/reset and stays editable for reproducible inspection.
Sources and editorial responsibility
Maintained by Renvoro Pty Ltd. Sources inform the methods and assumptions shown here; outputs have the limitations described on this page.
Method reviewed 2026-10-08. Calculation standards ยท Report an issue