Free JWT decoder, debugger & verifier
Paste a JSON Web Token to instantly decode its header and payload, verify the signature against a secret, public key, or JWKS/OIDC endpoint, and lint it against RFC 8725 best practices. Every known claim is annotated from a reference of 69 standard and vendor claims, timestamps like exp are translated to human dates, and algorithm confusion is flagged before it bites.
Private by architecture: all cryptography runs in your browser via the Web Crypto API — the token never leaves your device. No accounts, no analytics, works fully offline. How to verify that yourself.
- Generate RSA, EC, Ed25519 and HMAC keys — export as PEM, JWK or JWKS
- Encrypt and decrypt JWE tokens (JSON Web Encryption)
- Diff two JWTs to see changed, added and removed claims
New to tokens? Start with what a JWT actually is, how to decode one in code, which signing algorithm to use, or the attacks every verifier must survive.