JWT Debugger — decode, inspect and verify JWT tokens in your browser
JWT Debugger / Decoder
Paste any JWT to decode its three dot-separated parts — the base64url header, payload and signature are shown as
pretty-printed JSON with registered claims (exp, iat, nbf and friends) converted to your
local time. You can then verify the signature with the WebCrypto API: HMAC (HS256/384/512) with a secret, or RSA/ECDSA
(RS256/384/512, ES256/384/512) with a PEM public key, and a sample HS256 token is one click away for experiments.
Everything runs locally — tokens, secrets and keys are never sent anywhere.
Warning: this token declares alg:none, which means it is not signed.
Real services must reject unsigned tokens — treat it as untrusted.
Registered claims
Claim
Value
Interpretation
Verify signature
Secret
Public key (PEM)
crypto.subtle is not available in this context, so signature verification is disabled.
Open the page over https: or from a local file to enable it. Decoding still works.
How to read the result: the header usually carries alg (the signing algorithm) and typ.
Registered claims shown with local-time conversion are iat (issued at), nbf (not before) and
exp (expiration) — a red badge means the token has expired, amber means it expires within 24 hours.
Signature verification computes the same MAC the issuer would, or checks the RSA/ECDSA public key you paste,
then marks the token VALID or INVALID. Only algorithms implemented by the browser’s
WebCrypto layer can be verified; anything else is reported as unsupported rather than guessed at.
Common registered claims:sub (subject) is the user or entity the token is about —
in your sample it is just a numeric ID, but services often put an email, username, or UUID here.
iss names the issuer, aud names the intended audience, and jti is a unique token ID used to prevent replay.
These claims are not encrypted; anyone with the token can read them, so never put passwords or secrets in a JWT payload.
Privacy: decoding and verification happen entirely in this page with the WebCrypto API — the token,
your secret and any public key are never transmitted. For an alg:none token the page shows a clear warning:
unsigned tokens should never be accepted by a real API.
🔷 Code & Dev Tools
Developer utilities running entirely in your browser.