Local JWT Decoder & Verifier

Splits and decodes the header, payload, and signature of a JWT, interprets the standard claims (iss, sub, aud, exp, nbf, iat, jti) with configurable clock tolerance, and verifies the signature locally with HMAC (HS256/384/512), RSA (RS256/384/512), or EC (ES256/384) when you supply a compatible key. It explicitly distinguishes between decoded, not verified, verified, invalid signature, expired token, not-yet-valid token, malformed token, and disallowed algorithm — it never confuses decoding with verifying. It rejects alg:none by default and never mixes algorithm families (HMAC/RSA/EC) with a key of another type.

Processed on your device, no AIhasta 20.000 caracteres de token

The token, keys, and secrets stay on your device.

A decoded JWT isn't necessarily authentic. Authenticity requires verifying its signature with a trusted key.

or upload a file with the token

The data is processed on your device and is never sent to the server.

Use cases

How to use this tool

  1. Paste the JWT token
  2. Optionally supply the key or secret to verify the signature
  3. Review the status, claims, and report

Frequently asked questions

Does decoding the JWT mean it's authentic?
No. A decoded JWT isn't necessarily authentic: authenticity requires verifying its signature with a trusted key, which is an explicit, separate step in this tool.
Does it send the token or the key to any server?
No. The token, key, and secret stay on your device; verification is done locally with the browser's crypto.subtle.

Related tools

← Back to home