JWT Decoder
Decode and verify JSON Web Tokens. Your token never leaves your browser.
Decode a JWT
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwczovL2F1dGguZXhhbXBsZS5jb20iLCJzdWIiOiJ1c2VyXzhmMmMiLCJhdWQiOiJhcGkuZXhhbXBsZS5jb20iLCJuYW1lIjoiQWRhIExvdmVsYWNlIiwiZW1haWwiOiJhZGFAZXhhbXBsZS5jb20iLCJyb2xlcyI6WyJhZG1pbiJdLCJpYXQiOjE3OTAwMDAwMDAsImV4cCI6MTkwNjAwMDAwMH0.wAHKbmDH_A1NVzmvdiHoVj80jg71cGuKbnrGDCX9gOQ
Header
{
"alg": "HS256",
"typ": "JWT"
}
Payload
{
"iss": "https://auth.example.com",
"sub": "user_8f2c",
"aud": "api.example.com",
"name": "Ada Lovelace",
"email": "[email protected]",
"roles": [
"admin"
],
"iat": 1790000000,
"exp": 1906000000
}
Claims
| iss | https://auth.example.com | Issuer — who created and signed the token |
| sub | user_8f2c | Subject — who the token is about, usually a user ID |
| aud | api.example.com | Audience — who the token is meant for |
| name | Ada Lovelace | Full name |
| [email protected] | Email address | |
| roles | ["admin"] | Roles or groups |
| iat | 2026-09-21T14:13:20Z (in 0 seconds) | Issued at — when the token was created |
| exp | 2030-05-26T04:26:40Z (in 3 years) | Expiration time — reject the token after this |
What is inside the example token
The example is an access token signed with HS256. Its payload says who issued it
(iss), who it is about (sub), which API should accept it
(aud) and when it expires (exp, 2030). The demo secret is filled in
below the token, so the signature verifies; change one character of the token or the secret
and it fails. Paste your own token to replace it.
JWT signature verification in the browser
Most decoders only decode. JWT signature verification here uses your browser’s built-in Web Crypto, the same primitives servers use, for every algorithm in the JOSE standards: HMAC (HS256–HS512), RSA (RS and PS), elliptic-curve ECDSA (ES256–ES512) and Ed25519. It is tested against the example tokens in RFC 7515 and tokens signed by Node.js.
Decode JWT tokens from OAuth and OpenID Connect
Access tokens and ID tokens from Auth0, Okta, Microsoft Entra, Cognito, Firebase and
Keycloak are JWTs. To decode JWT tokens from them, paste the token; to
check the signature, paste the provider’s JWKS (from its /.well-known/jwks.json)
and the key with the matching kid is picked for you.