Sign up free

Online JWT Token Decoder and Verifier

Paste a JSON Web Token to read its header and payload, see when it expires and check the signature.

About JWT Decoder

A JWT decoder is the first stop when an API answers 401 or a login session ends too early. Paste the token and its header and payload appear as formatted JSON, so you can check the user ID, roles, issuer and audience. The exp, iat and nbf claims are shown as readable dates, with a clear note when the token has already expired or isn't valid yet.

Decoding alone proves nothing, because anyone can read a JWT. To trust one, verify its signature: enter the shared secret for HS256, HS384 or HS512, or the public key in PEM format for RS256 to RS512, PS256 to PS512 and ES256 to ES512. Tokens often carry personal data and grant access to accounts, so this one never leaves your browser. Nothing is uploaded or logged.

How to use JWT Decoder

  1. 1
    Paste the token

    Paste the whole JWT, the three parts separated by dots.

  2. 2
    Read the header and payload

    Both appear as formatted JSON, with exp, iat and nbf as dates.

  3. 3
    Check the status

    See whether the token is expired, not yet valid or current.

  4. 4
    Verify the signature

    Enter the secret for HS algorithms, or the PEM public key for RS, PS and ES.

Why use Cubfile for this

  • Readable claims

    Header and payload shown as pretty-printed JSON.

  • Dates, not numbers

    The exp, iat and nbf claims are converted, with expired and not-yet-valid warnings.

  • Signature check

    HS256/384/512, RS256/384/512, PS256/384/512 and ES256/384/512.

  • Token stays local

    Decoded and verified in your browser, never uploaded.

FAQ

JWT Decoder: questions and answers

Is it safe to paste a JWT into an online decoder?
Here it is, because decoding and verification run in your browser and the token is never sent anywhere. Still, treat a live token like a password and don't share it.
Can anyone read what's inside a JWT?
Yes. The header and payload are only Base64url-encoded, not encrypted, so never put passwords or secrets in them. The signature only stops people from changing them.
How do I verify a JWT signature?
For HS256, HS384 or HS512, enter the shared secret. For RS, PS and ES algorithms, paste the public key in PEM format. The result says whether the signature is valid. A PEM key pair for testing can be made with the RSA key generator.
Why does it say my token is expired?
The time in its exp claim is earlier than your device's clock. If the token should still be valid, check the server's clock and the lifetime set when the token was issued. To compare it with a Unix time from your server logs, use the Unix Timestamp Converter.
Which JWT algorithms are supported?
HS256, HS384 and HS512 with a secret, and RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 and ES512 with a PEM public key.
Share JWT Decoder with a friendIt runs in any browser, and they can try it without signing up.

Related tools

HASH Hash GeneratorGet MD5, SHA-1, SHA-256, SHA-512 and SM3 hashes of text in one go.
TIME Unix Timestamp ConverterConvert Unix timestamps to dates and back, in your time zone and UTC.
U+UNI Unicode ConverterConvert text to and from \u escapes, &#; codes, U+ points and UTF-8 bytes.
AES AES Encrypt and DecryptEncrypt or decrypt text with AES in GCM, CBC or CTR mode.
&;HTML HTML Entity Encoder/DecoderEscape text into HTML entities, or turn entities back into text.
01BIN Number Base ConverterConvert numbers between binary, octal, decimal, hex and any base up to 36.
BASE Base32 and Base58 EncoderEncode and decode Base32, Base58, Base85 and Base16.
0xHEX Text to Hex ConverterTurn text into hexadecimal bytes in UTF-8, GBK or UTF-16, and back.