JWT Decoder
Decode, inspect and verify JSON Web Tokens instantly.
Paste a JWT above — header, payload and claims are decoded instantly as you type.
JWT Algorithm Reference
| Algorithm | Family | Type | Key | Use Case |
|---|---|---|---|---|
| HS256 | HMAC-SHA256 | Symmetric | Shared secret | Single-server apps, APIs |
| HS384 | HMAC-SHA384 | Symmetric | Shared secret | Higher-security HMAC |
| HS512 | HMAC-SHA512 | Symmetric | Shared secret | Maximum HMAC security |
| RS256 | RSA-SHA256 | Asymmetric | RSA key pair | OAuth2, OIDC, microservices |
| RS384 | RSA-SHA384 | Asymmetric | RSA key pair | Higher-security RSA |
| RS512 | RSA-SHA512 | Asymmetric | RSA key pair | Maximum RSA security |
| ES256 | ECDSA P-256 | Asymmetric | EC key pair | Mobile, IoT, compact tokens |
| ES384 | ECDSA P-384 | Asymmetric | EC key pair | High-security EC |
| ES512 | ECDSA P-521 | Asymmetric | EC key pair | Maximum EC security |
| PS256 | RSASSA-PSS | Asymmetric | RSA key pair | FIPS-compliant systems |
| none | — | — | None | Unsecured — dev only |
Free JWT Decoder & Verifier
Paste any JSON Web Token and instantly see its decoded header, payload and signature, color-coded for clarity, with no server round-trip — decoding happens entirely in your browser using JavaScript, so the token never leaves your device.
It automatically detects and highlights expired, active and not-yet-valid tokens by reading the exp, iat and nbf claims, and can attempt signature verification: HS256/384/512 tokens verify client-side with a secret key you provide, while RS256/ES256 tokens can be checked against a public key in PEM format.
Key features
Instant, client-side decoding
Header and payload decode as you type — nothing is sent to any server.
Expiry detection
Automatically flags expired, active and not-yet-valid tokens based on exp/iat/nbf.
Signature verification
Verify HS256/384/512 signatures with a secret key, right in the browser via the Web Crypto API.
Color-coded parts
Header, payload and signature are visually separated for quick scanning.
How to use it
- Paste a JWT into the input box.
- Review the decoded header and payload, color-coded for clarity.
- Check the automatically detected expiry status (expired/active/not-yet-valid).
- Optionally paste a secret key or public PEM key to attempt signature verification.
Worked example
Example
A token with payload {"sub":"1234567890","name":"Ana","exp":1735689600} decodes to show the header algorithm (e.g. HS256), the claims above, and a status flag showing whether the exp timestamp has already passed.Who uses this tool
Developers
Debug authentication issues by inspecting exactly what claims a token carries.
API testers & QA engineers
Verify a token's expiry and claims before using it in a test request.
Students learning web auth
See how a JWT's three Base64URL-encoded parts (header, payload, signature) fit together.
Tips for the best results
- Always check the exp claim before assuming a token is still valid — the tool flags this automatically.
- Use HS256 signature verification to confirm a token was actually issued by a service that knows your shared secret.
- For RS256/ES256 tokens, you need the issuer's public key in PEM format to verify — the signature bytes alone aren't enough.
- Never paste a production secret key into any online tool as a general habit — this one verifies entirely client-side, but always confirm that before using any tool with sensitive keys.
Common mistakes to avoid
- Trusting a token's payload without verifying its signature — anyone can craft a fake JWT with arbitrary claims if the signature isn't checked.
- Treating exp, iat and nbf as encrypted or hidden — JWT payloads are only Base64-encoded, not encrypted, and are readable by anyone who has the token.
- Accepting a token with "alg: none" — this means no signature is required at all, letting anyone forge the token.
Why use AZRS QuickFix?
It is 100% free, needs no signup and has no watermark or usage limits. The tool runs in your browser, so what you type stays on your device, and it works on phones, tablets and desktops. New tools are added every week — bookmark this page or browse the full QuickFix toolbox.
Frequently asked questions
Is it safe to paste my JWT here?
Yes. This tool decodes entirely in your browser using JavaScript; your token is never sent to any server, which you can confirm using the browser's Network tab.
What is a JWT?
A JSON Web Token is a compact, URL-safe format for representing claims between parties, made of three Base64URL-encoded parts: a header, a payload and a signature.
Can this tool verify the signature?
For HS256/384/512 tokens, enter your secret key and it verifies client-side. For RS256/ES256, paste the public key in PEM format to attempt verification.
What do exp, iat and nbf mean?
exp is the expiration timestamp, iat is when the token was issued, and nbf is the earliest time the token should be accepted — all converted to readable dates automatically.
What's the difference between HS256 and RS256?
HS256 uses one shared secret for signing and verifying; RS256 uses a private key to sign and a separate public key to verify, common in distributed systems.
Why is "alg: none" dangerous?
It means no signature is required, so an attacker can forge any token by crafting the header and payload without signing it — servers should always reject it.