JWT Debugger
Security & IdentifiersDecode, inspect, and verify JSON Web Tokens
Encoded Token
Decoded
Header
Payload
Signature · HS256
ikcZpHFjgZTlYAAAIsP41LJ459WWmSVwIgAlw-_1ykg
About the JWT Debugger
A JWT debugger for the moment you need to know what's actually inside a token, not just that it's a token. Paste one in and see the header and payload as readable, colorized JSON, expiration and issued-at claims called out as dates instead of raw timestamps, and — if you have the secret or public key — a live signature check.
Debugging auth issues usually means answering three questions fast: what claims does this token actually carry, has it expired, and is the signature even valid. This tool answers all three in one paste, entirely client-side — which matters, since a JWT payload and any secret or private key used to verify it are exactly the kind of thing you don't want leaving your machine.
How to Use the JWT Debugger
Paste a JWT into the input field.
Review the decoded header and payload, with exp/nbf claims flagged.
Optionally paste a secret or public key to verify the signature.
Frequently Asked Questions
Is my token, secret, or private key uploaded anywhere?
No. Decoding and signature verification both run locally via the browser's Web Crypto API — nothing you paste, including a signing secret or private key, is ever sent anywhere. That matters here more than in most tools, since you might be pasting real credentials.
What does "alg: none" mean, and why is it flagged?
It means the token claims to be unsigned. Accepting alg: none tokens is a well-known JWT vulnerability — a client could forge any payload with no signature at all — so the tool calls it out explicitly instead of quietly showing an empty signature.
Which signing algorithms can be verified?
HS256/384/512 with a shared secret, and RS256/384/512 or ES256/384/512 with a PEM-encoded public key (-----BEGIN PUBLIC KEY-----). Other algorithms, like the PS* family, are decoded but not verified yet.
Why do exp, iat, and nbf show as dates instead of numbers?
Per RFC 7519, those claims are Unix timestamps in seconds. The tool converts them to your local time and flags an expired exp or a not-yet-active nbf, so you don't have to do the math by hand.
Can I use this on a production access token?
Yes — that's exactly the use case it's built for. Since verification runs entirely in your browser with nothing transmitted, it's safe to paste a real, live token to check its claims or confirm its signature, unlike a server-side JWT debugger.