JWT Decoder
Paste a JSON Web Token to see its header and payload as formatted JSON, with issued-at and expiry times turned into readable dates. You can also verify a signature or sign a test token.
How to use it
- Paste the token.
- Read the decoded header and payload.
- To check the signature, choose Verify signature and enter the secret or public key.
What it does
- Decodes header and payload, with exp, iat and nbf shown as dates
- Verifies HMAC signatures, and RSA and ECDSA ones with a PEM public key
- Signs HS256, HS384 and HS512 test tokens
- Secrets are never saved or put in share links
Questions
- Is it safe to paste a production JWT?
- The token is decoded on your device and never sent anywhere. Even so, treat live tokens with care.
- Can it verify the signature?
- Yes. Choose Verify signature and enter the shared secret or the PEM public key.
- Why does my token show as expired?
- The exp claim is in the past. Bracely shows the exact expiry time next to it.
More JSON tools
Bracely has more than 60 JSON tools in one page. Related ones:
Runs entirely in your browser. Nothing you paste is uploaded. Privacy policy