JWT Debugger / Decoder

Paste any JWT to decode its three dot-separated parts — the base64url header, payload and signature are shown as pretty-printed JSON with registered claims (exp, iat, nbf and friends) converted to your local time. You can then verify the signature with the WebCrypto API: HMAC (HS256/384/512) with a secret, or RSA/ECDSA (RS256/384/512, ES256/384/512) with a PEM public key, and a sample HS256 token is one click away for experiments. Everything runs locally — tokens, secrets and keys are never sent anywhere.
JWT token Format: header.payload.signature (three base64url segments).
Warning: this token declares alg:none, which means it is not signed. Real services must reject unsigned tokens — treat it as untrusted.
ClaimValueInterpretation
Secret
crypto.subtle is not available in this context, so signature verification is disabled. Open the page over https: or from a local file to enable it. Decoding still works.
How to read the result: the header usually carries alg (the signing algorithm) and typ. Registered claims shown with local-time conversion are iat (issued at), nbf (not before) and exp (expiration) — a red badge means the token has expired, amber means it expires within 24 hours. Signature verification computes the same MAC the issuer would, or checks the RSA/ECDSA public key you paste, then marks the token VALID or INVALID. Only algorithms implemented by the browser’s WebCrypto layer can be verified; anything else is reported as unsupported rather than guessed at.

Common registered claims: sub (subject) is the user or entity the token is about — in your sample it is just a numeric ID, but services often put an email, username, or UUID here. iss names the issuer, aud names the intended audience, and jti is a unique token ID used to prevent replay. These claims are not encrypted; anyone with the token can read them, so never put passwords or secrets in a JWT payload.

Privacy: decoding and verification happen entirely in this page with the WebCrypto API — the token, your secret and any public key are never transmitted. For an alg:none token the page shows a clear warning: unsigned tokens should never be accepted by a real API.