Valid JWTEnter a secret or public key to verify the signature.

JWT debugger

Paste a token to decode the header and payload, then verify the signature with your key.

Encoded header length: 36

Encoded payload length: 91

Signature length: 43

{
  "alg": "HS256",
  "typ": "JWT"
}
{
  "sub": "1234567890",
  "name": "John Doe",
  "admin": true,
  "iat": 1516239022
}

Claims Breakdown

sub•1234567890
iat•1516239022 (2018-01-18 01:30:22 UTC)
name•John Doe
admin•true

About the JWT Debugger

A JSON Web Token looks like three chunks of gibberish separated by dots, but it's really just a header and payload encoded in Base64 plus a signature. This page splits a token apart so you can read the claims inside it, check a signature against a secret, or put together a new token while you're testing an API — all without the token ever leaving your browser tab.

Things you can do here

  • •Decode — paste any JWT and instantly read its header and payload as formatted JSON.
  • •Verify — check the token's signature against a secret to confirm it hasn't been tampered with.
  • •Encode — switch to the encoder tab to build and sign a brand-new token from your own header and payload.
  • •Generate an example — load a sample token instantly if you just want to see how the tool works.
  • •Copy — copy the token, header, or payload with a single click.

How to use the JWT Debugger

  1. Paste a JWT to inspect its header and payload.
  2. Review claims and expiration details.
  3. Use a suitable secret or public key when verifying a signature.
Example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

JWT Debugger FAQ

Is decoding a JWT the same as verifying it?

No. Decoding reads the token contents; verification checks whether its signature matches a trusted key.