Encoders & Decoders
JWT Toolkit
Decode JWTs, inspect claims, verify HMAC signatures, and generate HS256, HS384, or HS512 tokens locally. Signing uses a shared secret in your browser — JWTs are not encrypted.
Paste a JWT to decode its header and payload. Signature is not verified.
Sample tokens are signed with the public demo secret
devztools-demo-secret.
That secret is for local examples only — not for production.
Decoded parts
Decoding reveals the token’s header and payload. It does not prove authenticity. A future expiration does not mean the signature is valid. Use Verify signature with the HMAC secret to check authenticity (HS256, HS384, or HS512 only).
Claims summary
Verify signature (HMAC)
Optional: enter the shared secret to verify HS256, HS384, or HS512 signatures. Decoding above does not verify the signature.
JWT output
Read-only
Signed header
Read-only
Signed payload
Read-only
About this tool
JWT Toolkit inspects header alg,
expiration (exp), and not-before (nbf)
using your local clock, verifies HMAC signatures, and generates
HS256, HS384, or HS512 tokens with Web Crypto. Decoding
shows contents only — it is not authenticity. Generation
uses a shared HMAC secret and does not encrypt the payload.
- Runs entirely in your browser
-
HMAC signing and verification use the Web Crypto API (HS256, HS384, HS512 only). RSA, ECDSA, and
alg: nonegeneration are not offered. - Tokens and secrets are not stored or logged
- Decoding does not verify the signature unless you explicitly verify with a secret