JWT Decoder
Paste a token — see expiry, claims, and payload instantly. Optional HMAC verify. Nothing uploaded.
Tokens & secrets never leave your browser
Waiting for a token
Paste a JWT — decoding stays in your browser
Verify signature (HS256 / HS384 / HS512)
Optional. RSA/ECDSA not in this version. Example secret: devdock-secret
Sponsored
Ad space
How to decode a JWT
- Paste a JWT (or a full Bearer … header value).
- Read the status strip: Active, Expired, or Not yet valid — with a live countdown.
- Copy standard claims or the pretty header / payload JSON.
- Optionally enter the HMAC secret and tap Verify (HS256 / HS384 / HS512).
Why a local JWT decoder beats pasting into chat
Access tokens often carry user IDs, roles, and tenant data. Pasting them into an AI chat or an unknown online debugger risks leaking credentials. A client-side decoder gives you the same answers — algorithm, expiry, claims, HMAC check — with a live clock and zero upload. That is the loop developers actually run when APIs return 401s.
FAQ
Is my JWT uploaded?
No. Decoding and HMAC verification run in your browser with the Web Crypto API. DevDock never sends your token or secret to a server.
What do Active / Expired / Not yet valid mean?
Active means the current time is within nbf (if present) and before exp (if present). Expired means exp is in the past. Not yet valid means nbf is still in the future. Missing exp is allowed but flagged as a warning.
Which algorithms can I verify?
HS256, HS384, and HS512 with a shared secret. Decoding works for any JWT (including RS/ES) — asymmetric signature check is not in this version.
Why warn about alg none or missing exp?
alg none means there is no integrity check. Missing exp means the token never expires. Both are common footguns when debugging auth — the tool surfaces them without blocking decode.
Can I paste a Bearer header?
Yes. A leading Bearer prefix and whitespace are stripped automatically so you can paste straight from Authorization headers.
Can I paste a token wrapped in quotes?
Yes. Surrounding double or single quotes from JSON or config files are removed before decode.
Need to inspect JSON payloads? Try the JSON Formatter. Working with Base64 segments? Use Base64 Encode / Decode. Checking token digests? Open the Hash Generator.
Sponsored
Ad space