Paste a JSON Web Token to read its header and payload, see human-readable timestamps and check whether it is expired. You can also sign an HS256 token from your own payload. Everything runs locally — tokens and secrets never leave your browser.
A UUID identifies a record — never use it as an authentication token.
Math.random() is predictable. Use the CSPRNG for tokens, IDs and secrets.
Decoding is not verifying. Always validate the signature and claims on the server.
Generate keys here, then store them in environment variables or a vault.
Paste a JSON Web Token to read its header and payload, see human-readable timestamps and check whether it is expired. You can also sign an HS256 token from your own payload. Everything runs locally — tokens and secrets never leave your browser.
Paste any JWT into the decode box — the header and payload appear instantly.
Issuer, subject, issued-at and expiry are highlighted with readable dates and an expired/valid badge.
Enter a payload and secret in the sign tab to produce an HS256 token you can test with.
| Claim | Meaning | Example |
|---|---|---|
| iss | Issuer | auth.example.com |
| sub | Subject / user id | 1234567890 |
| iat | Issued at (Unix time) | 1700000000 |
| exp | Expires at (Unix time) | 1700003600 |
Times are Unix timestamps in seconds — the decoder converts them for you.
It is completely free, private and requires no signup.
Use the tool nowYes. Decoding happens fully in your browser; the token is never transmitted. Still, avoid pasting production tokens on shared machines.
No. Anyone can read and forge the payload — only a server-side signature check proves authenticity.
HS256 uses one shared secret for signing and verifying. RS256 uses a private key to sign and a public key to verify.
The decoder does not know your secret, so it can only display the signature. Verification always requires the key.
Explore the whole collection — no signup, 100% free & private.