Encoders & Decoders

JWT Toolkit

Decode JWTs, inspect claims, verify HMAC signatures, and generate HS256, HS384, or HS512 tokens locally. Signing uses a shared secret in your browser — JWTs are not encrypted.

Paste a JWT to decode its header and payload. Signature is not verified.

Sample tokens are signed with the public demo secret devztools-demo-secret. That secret is for local examples only — not for production.

Decoded parts

Header
Payload
Signature

Decoding reveals the token’s header and payload. It does not prove authenticity. A future expiration does not mean the signature is valid. Use Verify signature with the HMAC secret to check authenticity (HS256, HS384, or HS512 only).

Verify signature (HMAC)

Optional: enter the shared secret to verify HS256, HS384, or HS512 signatures. Decoding above does not verify the signature.

About this tool

JWT Toolkit inspects header alg, expiration (exp), and not-before (nbf) using your local clock, verifies HMAC signatures, and generates HS256, HS384, or HS512 tokens with Web Crypto. Decoding shows contents only — it is not authenticity. Generation uses a shared HMAC secret and does not encrypt the payload.

  • Runs entirely in your browser
  • HMAC signing and verification use the Web Crypto API (HS256, HS384, HS512 only). RSA, ECDSA, and alg: none generation are not offered.
  • Tokens and secrets are not stored or logged
  • Decoding does not verify the signature unless you explicitly verify with a secret