TsWorks Tools
All tools (39)

JWT Decoder

Decode and verify a JSON Web Token without sending it anywhere.

Paste a JWT. Nothing is uploaded - this page has no network calls after it loads.

Decode a JWT without handing it to a server

Paste a JSON Web Token and its header and payload are decoded immediately. The registered claims are expanded underneath -exp, nbf and iat as readable timestamps with how long ago or how far ahead they are, and an expired token called out clearly.

This matters more than it sounds. A JWT is a bearer credential: anyone holding it can act as its subject until it expires. Pasting a production token into a site that decodes it server-side hands that credential to whoever runs the site. Everything here happens in this tab, and the page makes no network requests after it loads.

Verifying the signature

Decoding proves nothing - the header and payload are just base64url, readable by anyone. Verification is what tells you the token is genuine. Supply the key and this checks it with the browser's own WebCrypto implementation:

  • HS256 / HS384 / HS512 - paste the shared secret as text.
  • RS256 / RS384 / RS512 and PS256 / PS384 / PS512 - paste the SPKI public key (-----BEGIN PUBLIC KEY-----) or a JWK.
  • ES256 / ES384 / ES512 - the same, for P-256, P-384 and P-521 keys.

For RSA and ECDSA you only need the public key, which is published at the issuer's JWKS endpoint. You should never need a private key to verify a token.

Why "alg": "none" is flagged

A token whose header says alg: none has no signature. Anyone can rewrite its payload - change admin totrue, change the subject - and it stays "valid" to a verifier that trusts the header. Every JWT library has shipped a version of this bug. Your verifier should decide which algorithm to expect from your own configuration, never from the token.

Frequently asked

Can a JWT be decrypted without the key?

A signed JWT (JWS, three parts) is not encrypted at all - the payload is plain base64url and anyone can read it, which is why secrets do not belong in one. A five-part token is a JWE, which genuinely is encrypted and cannot be read without the key.

Why does my token fail to verify?

Usually one of: the wrong key for the environment, a secret that is base64-encoded at the issuer but pasted here as text, whitespace picked up in a copy-paste, or a token truncated by the field you copied it from.

Related tools