Free JWT decoder, debugger & verifier

Paste a JSON Web Token to instantly decode its header and payload, verify the signature against a secret, public key, or JWKS/OIDC endpoint, and lint it against RFC 8725 best practices. Every known claim is annotated from a reference of 69 standard and vendor claims, timestamps like exp are translated to human dates, and algorithm confusion is flagged before it bites.

Private by architecture: all cryptography runs in your browser via the Web Crypto API — the token never leaves your device. No accounts, no analytics, works fully offline. How to verify that yourself.

New to tokens? Start with what a JWT actually is, how to decode one in code, which signing algorithm to use, or the attacks every verifier must survive.