About JWT Decoder
A JWT decoder is the first stop when an API answers 401 or a login session ends too early. Paste the token and its header and payload appear as formatted JSON, so you can check the user ID, roles, issuer and audience. The exp, iat and nbf claims are shown as readable dates, with a clear note when the token has already expired or isn't valid yet.
Decoding alone proves nothing, because anyone can read a JWT. To trust one, verify its signature: enter the shared secret for HS256, HS384 or HS512, or the public key in PEM format for RS256 to RS512, PS256 to PS512 and ES256 to ES512. Tokens often carry personal data and grant access to accounts, so this one never leaves your browser. Nothing is uploaded or logged.
How to use JWT Decoder
- 1Paste the token
Paste the whole JWT, the three parts separated by dots.
- 2Read the header and payload
Both appear as formatted JSON, with exp, iat and nbf as dates.
- 3Check the status
See whether the token is expired, not yet valid or current.
- 4Verify the signature
Enter the secret for HS algorithms, or the PEM public key for RS, PS and ES.
Why use Cubfile for this
- Readable claims
Header and payload shown as pretty-printed JSON.
- Dates, not numbers
The exp, iat and nbf claims are converted, with expired and not-yet-valid warnings.
- Signature check
HS256/384/512, RS256/384/512, PS256/384/512 and ES256/384/512.
- Token stays local
Decoded and verified in your browser, never uploaded.