gettoolz.app

JWT Decoder

Decode a JWT’s header and payload, read its expiry claims, and verify its signature locally.

Part of developer tools and security tools.

Your JWT

What this tool does

Paste a JSON Web Token and its header and payload are decoded and pretty-printed as JSON, each with its own copy button. If the token carries an exp, iat or nbf claim, it is converted from a Unix timestamp into a readable UTC date, alongside a badge showing whether it is expired, valid, or not yet active.

The third segment — the signature — is shown exactly as it was sent, as raw Base64URL text. Paste the signing secret or public key into the optional “Verify the signature” panel and it is checked right in your browser.

Verifying the signature locally

Decoding alone proves nothing: the header and payload are just Base64URL-encoded JSON, and anyone can forge a token with any claims. Open “Verify the signature” and paste the HMAC secret (HS256, HS384, HS512 — as text, or Base64 with the checkbox) or the RSA public key (RS256, as a BEGIN PUBLIC KEY PEM or a JWK). The signature over header.payload is recomputed with your browser’s built-in Web Crypto API and you get a clear valid or invalid verdict, updated as soon as the token or key changes.

The key is never put in the URL, never stored and never sent anywhere — no network request is made. Limits: ES256 and other algorithms are not supported yet, PKCS#1 keys (BEGIN RSA PUBLIC KEY) must be converted to SPKI first, remote JWKS URLs are not fetched, and alg: none is never reported as valid. A valid signature does not check audience, issuer or revocation: your server still has the final word.

Handles the edge cases

A Bearer prefix, and any stray whitespace or line breaks from copying out of a terminal or an Authorization header, are stripped automatically. Tokens signed with alg: none — which have only two segments, or a third, empty one — decode without a signature. Anything that isn’t shaped like a JWT, or whose header or payload isn’t valid Base64URL or JSON once decoded, shows a clear error instead of crashing.

Is my data safe?

Yes. Decoding and signature checks happen entirely in your browser — nothing you paste is sent to a server, so it is safe to inspect tokens carrying real session data. The page loads no ads, no analytics and no third-party scripts of any kind.