JWT Decoder
Paste a JSON Web Token to read its header and payload, check the expiry, and optionally verify an HS256 signature. Everything happens in your browser — your token is never uploaded.
New to this? Read the JWT Decoder guide →
Verify HS256 signature
Optional — only for HMAC-SHA256 tokens. The secret stays in your browser.
Header
—
Payload
—
Paste a JWT to decode it.