How to use
- Paste the token. It never leaves this page.
- Read the header, payload and claim times.
- Optionally paste a secret or public key to verify the signature.
Worked example
A payload with "exp": 1767225600 shows “Expires 1 Jan 2026, 00:00 UTC” and whether that is in the past.
Supported formats and limits
| Input | JWT (JWS compact), Secret, PEM or JWK for verification |
|---|---|
| Output | Header, payload, claims |
| Engine | Base64URL decoding; jose for signature verification |
Limitations
- Decoding does not prove a token is genuine; only signature verification with the right key does.
- A valid signature does not check the issuer, audience or other claims your application relies on.
- Encrypted tokens (JWE) cannot be decoded without the key; only their header is shown.
Questions
Does decoding a JWT prove it is valid?
No. Anyone can create a token with any claims, and the header and payload are only Base64URL-encoded JSON. Only verifying the signature with the issuer's secret or public key shows it was signed by that key, and your application must still check claims such as issuer and audience.
Which keys can verify a signature?
A shared secret for HS256, HS384 and HS512, or a public key as PEM (SPKI or X.509 certificate), JWK or JWK Set for RS, PS, ES and EdDSA algorithms. Only the algorithm in the token header is accepted.
How are expiry times shown?
exp, nbf, iat and similar claims are shown as dates in your device's time zone with a relative time, and the token is marked expired, not yet valid or current against your device clock. An exp of 1767225600 is 1 Jan 2026, 00:00 UTC.
Privacy
Runs on your device. Files and text are processed in this browser tab and are not uploaded.
See the privacy policy for how toolsdocks handles data.