JWT Decoder

Decode a compact signed JWT locally, inspect its header/payload and interpret time claims. Optionally verify HS256 with your supplied secret or RS256 with an SPKI public key, using browser cryptography.

Change to evaluate dates at a specific time.

How the calculation works

JWT segments use base64url. The signing input is encoded header + "." + encoded payload. Optional verification checks the signature using HMAC SHA-256 or RSA PKCS#1 v1.5 SHA-256. iat, nbf and exp are Unix timestamps.

Worked example

The included demonstration token has a header and payload that can be decoded; its dummy signature is not verified. An exp value at or before the entered current Unix time is labelled expired.

Assumptions and limitations

Decoding does not authenticate a token. A matching signature does not establish issuer, audience, authorization, key trust or full application validity. This supports compact three-part signed tokens, not five-part encrypted JWE. Verification rejects unsupported algorithms and critical extensions.

Use synthetic or non-production tokens when possible. Never provide a private RSA key; RS256 requires a public SPKI PEM key. Token/key data stays in this tab, with no share state or server draft. Reference time defaults to your browser clock on page load/reset and stays editable for reproducible inspection.

Sources and editorial responsibility

Maintained by Renvoro Pty Ltd. Sources inform the methods and assumptions shown here; outputs have the limitations described on this page.

Method reviewed 2026-10-08. Calculation standards ยท Report an issue