Developer tool · runs in your browser
JWT decoder: read a token and check its signature
Paste a token into the field below. The header, payload and time claims decode as you type. Add the secret or public key to verify the signature. The token is not sent to a server.
- Free · no account · no job limit
- Local · nothing is uploaded
- Verifies HS, RS, PS and ES signatures
Encoded token
Sample loadedThe field starts with a sample token signed with the secret wolutools-demo-secret, so every panel shows a real result. Select the sample and paste your own token over it.
Header
Payload
Claims and expiry
| Claim | Value | Reading |
|---|
Times are shown in your local zone and in UTC. Registered claims follow RFC 7519; anything else is application-specific.
Signature
Paste the matching entry from the issuer's JWKS document. Only the public half is needed, and it stays on this page.
Decoding is not trust. Anyone holding a token can read its payload. A token only means something once its signature has been checked against a key you already trust, and whether your system accepts it is decided by your own server settings.
Open the full-page workspaceThe same tool on its own page, with notes on padding, alg: none and what verification can check.
From token to answer in three steps
- 1
Paste the JWT
The token is split into header, payload and signature as you type. A malformed token gets an error that says which part failed and why.
- 2
Read the claims
Registered claims such as issuer, audience and expiry are labelled. Timestamps appear as dates with a relative reading, and the token is marked as expired, not yet valid or within its validity window.
- 3
Verify the signature
For HMAC tokens, type the shared secret. For RSA or ECDSA tokens, paste the public key as a JWK. The check runs through Web Crypto in your browser and the key stays on the page.
Reading a JWT and checking its signature in your browser
What a JWT is
Three Base64URL strings joined by dots. The first two are JSON: a header that names the signing algorithm, and a payload of claims. The third is a signature over the first two, exactly as they appear in the string. Decoding the first two needs no key, which is why a token's payload should never hold secrets.
What the decoder shows
Every claim in the payload is listed. Registered names are labelled, and the time claims exp, nbf, iat, auth_time and updated_at are converted to dates in your local zone and in UTC. A token with alg set to none, a missing alg or an unknown algorithm gets a warning. A five-part token is recognised as an encrypted JWE, which cannot be read without the decryption key.
Verifying the signature
HMAC algorithms (HS256, HS384, HS512) use one shared secret for signing and verifying, so the secret is enough. RS, PS and ES algorithms verify with the issuer's public key, which you paste as a JWK. The page does not fetch a JWKS document for you and does not check revocation, the issuer or the audience. Those checks belong in your application.
No limit, no stored results
This is one of the 37 WoluTools tools that run free in the browser. The allowance of 3 free jobs a day and the result windows apply to tools that process files on the server. Here nothing is uploaded and nothing is kept, so there is no job to count and no result to expire.
Questions before you paste a token
Is it safe to paste a JWT into this page?
The token is decoded by a script on this page and is not sent to a server. The page makes no network request for the token or for a key you paste. Keep in mind that anyone who holds a valid token can use it until it expires, so treat live tokens with the same care as a password.
Can it verify a token's signature?
Yes, for HS256, HS384 and HS512 with the shared secret (as plain text or as Base64 bytes), and for RS, PS and ES algorithms with the issuer's public key pasted as a JWK. The check runs through Web Crypto in your browser. EdDSA and unknown algorithms are decoded but not verified. A JWKS document is not fetched automatically; copy the matching key across yourself.
Which claims does it show?
Every claim in the payload is listed in a table. Registered names such as iss, sub, aud, exp, nbf, iat and jti are labelled. The time claims exp, nbf, iat, auth_time and updated_at are shown in your local time and in UTC, with a relative reading such as “in 3 days” or “2 hours ago”. The token is marked as expired, not yet valid, within its validity window or without an exp claim.
What happens with alg: none?
The page shows a warning. A token with alg set to none has no signature, so anyone who holds it can change its contents. Your verifier should choose the accepted algorithm from its own configuration and reject none.
Does it handle encrypted JWE tokens?
A JWE has five parts instead of three. The page recognises it and tells you so, but it cannot decrypt it, because that needs the decryption key.
Why does a token decode here but fail in my library?
JWTs drop the trailing = padding of Base64URL. This page adds the padding back before decoding; some libraries do not. If a token works here but not in your code, check the padding first.