Skip to content
WebDevTools

JWT Debugger — Decode, Verify & Sign

Decode JSON Web Tokens, check expiry, verify HS/RS/ES/PS signatures and sign new tokens. Keys and tokens never leave your browser.

Runs locally in your browser

What is a JWT?

A JSON Web Token is a compact, URL-safe token made of three Base64URL parts separated by dots: header (algorithm and type), payload (claims such as sub, exp, iat) and signature. JWTs are widely used for API authentication and single sign-on.

What this tool does

  • Decode any token and pretty-print its header and payload.
  • Show time claims (iat, nbf, exp) as readable dates and tell you whether the token is expired.
  • Verify the signature with a shared secret (HS256/384/512) or a public key in PEM or JWK format (RS*, PS*, ES*).
  • Sign new tokens for testing, from your own header, payload and key.

Security notes

  • Decoding does not prove a token is genuine; only signature verification does.
  • Tokens with alg: "none" are unsigned and should always be rejected by servers.
  • Your tokens and keys are processed with the browser’s Web Crypto API and are never sent anywhere or saved.