mockstack.

JWT Decoder

HEADER · PAYLOAD ← Developer & Data

Read the header, payload, and expiry of a token.

JWT
This token is unsigned (alg “none”). Anything could have written it, and a server must never accept it.
Verify

HS256, HS384, and HS512 take the shared secret. RS, PS, ES, and EdDSA take the public key, as PEM, a certificate, or a JWK or JWKS set.

Header
Payload
READY THE TOKEN IS NEVER SENT ANYWHERE

About the JWT Decoder

Opens a login token and shows what is inside, without sending it anywhere. Paste the token: the header and claims decode instantly, every three-letter field gets a plain explanation, and expiry counts down in real time.

Every Setting

Paste a Token
Paste the token on its own or straight from a request header; an Authorization: Bearer prefix is skipped.
Token Strip
Under the box, the pasted JWT colored by part: header, payload, signature, with the algorithm and a live expiry badge. A token signed with alg none gets a red warning, because anything could have written it.
Header and Payload
The two decoded halves side by side. Copy puts the payload JSON on the clipboard; the payload stays editable for re-signing.
Claims Table
Each claim decoded and explained: iss, sub, aud, exp and the rest in plain words, with timestamps turned into real dates.
Token
In the rail: Load the Sample Token fills the box with a working self-signed token to explore, and Clear resets the page.
Verify
Right under the token: shared-secret tokens (HS256 and family) verify live against the secret you type. Public-key tokens (RS, PS, ES, and EdDSA) get a box for the public key instead, which takes a PEM public key, a certificate, or a JWK. Paste a whole JWKS set, like the one at an identity provider’s /.well-known/jwks.json, and the key is picked by the token’s kid.
Pane Divider
Drag the bar between Header and Payload to deal the width; it remembers your split, and double-clicking resets it. Left alone, the payload gets the room.
Edit and Re-Sign
Change the payload and press Re-Sign With Secret to mint a new token with the secret from the rail, which is how you build test tokens. The sample token verifies with the secret shown, so you can watch the whole flow work.
Cheat Sheet
The drawer lists the standard three-letter claims (iss, sub, aud, exp and the rest) with what each one means.

Common Questions

Is pasting a token here safe?
Treat production tokens like passwords and prefer expired ones for debugging.
Why does my token show as expired?
The exp claim is compared against your clock, live. A token that just expired says so the moment it happens.

Related: JWT Security Basics, Base64 and URL Encoder.