JWT Decoder / Generator
About this tool
A JWT has three dot-separated parts — header, payload and signature — and the first two are base64url-encoded JSON. Decode shows both, and converts time claims like exp, iat and nbf to this device's time along with whether the token has expired.
With a secret, HS256/HS384/HS512 signatures are recomputed using the browser's WebCrypto (crypto.subtle) HMAC and compared with the token. Generate mode signs a header and payload the same way to create a new token. Public-key signatures such as RS256 are not verified.
Tokens and secrets never leave this device, so pasting a production token leaves nothing on a server. Still, anyone can decode a payload, so never put values like passwords in it.
FAQ
Is my token sent to a server?
No. Decoding and signing both happen in your browser.
Can it verify RS256?
It decodes any JWT, but only verifies HS256, HS384 and HS512 signatures.
Why does exp show expired?
exp is a Unix time in seconds; if it is before this device's current time, the token is shown as expired.