Free Online JWT Decoder, Signature Verifier and Token Builder
Read what is inside a JSON Web Token, check that its signature is genuine, and sign a token of your own for testing. The header and payload are shown as formatted JSON with the times turned into real dates, the signature is checked against a shared secret or an RSA public key, and the issuer and audience can be checked too.
| Time claim | When (UTC) |
|---|
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
Verifying Here, and What It Costs You
One of the two ways costs you nothing at all.
A JWT has three parts: a header, a payload, and a signature. The first two are only Base64URL encoded JSON, readable by anyone, which is why the decoder needs nothing from you. The signature proves the token was issued by someone holding the key, and checking it means having that key. Which key depends on how the token was signed, and the difference matters more than it looks.
Where Your Input Goes
Nowhere. And you can check that yourself.
How to Read, Verify or Sign a JWT
Three jobs on one page, and nothing is uploaded.
What to Know About JWTs
Including the things this tool cannot do.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About the JWT Encoder and Decoder
A JWT turns up whenever you are working with authentication: a session token, an API key in bearer form, a link that logs someone in. It looks like a wall of Base64, and the quickest way to understand a bug is to see what is actually inside it. That is what this does, in your browser, the moment you paste one in.
It shows the header and the payload as readable JSON, names the signing algorithm, and turns the cryptic timestamps into real dates, then tells you whether the token has expired. If you want more than that it will check the signature, against an RSA public key, which is not a secret at all, or against a shared secret, which is. It will also sign an HMAC token with a payload of your own, which is the quickest way to get a token for exercising an endpoint.
The tool doubles as a reminder of two things people get wrong about JWTs: the payload is readable by anyone, so nothing secret belongs in it, and the token is signed but not encrypted, so being able to read it is the format working correctly. Decoding a token you hold shows you exactly what any recipient can see, which is often the point of checking.
Frequently Asked Questions
Signatures, claims, and why nothing secret belongs in a payload.
Every Other Security Tool
10 more tools in this set. All free, all in your browser.