About the JWT Debugger
A JSON Web Token looks like three chunks of gibberish separated by dots, but it's really just a header and payload encoded in Base64 plus a signature. This page splits a token apart so you can read the claims inside it, check a signature against a secret, or put together a new token while you're testing an API — all without the token ever leaving your browser tab.
Things you can do here
- •Decode — paste any JWT and instantly read its header and payload as formatted JSON.
- •Verify — check the token's signature against a secret to confirm it hasn't been tampered with.
- •Encode — switch to the encoder tab to build and sign a brand-new token from your own header and payload.
- •Generate an example — load a sample token instantly if you just want to see how the tool works.
- •Copy — copy the token, header, or payload with a single click.
How to use the JWT Debugger
- Paste a JWT to inspect its header and payload.
- Review claims and expiration details.
- Use a suitable secret or public key when verifying a signature.
Example:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...JWT Debugger FAQ
Is decoding a JWT the same as verifying it?
No. Decoding reads the token contents; verification checks whether its signature matches a trusted key.