How to use
- Paste the token into the box. A leading Bearer and any line breaks are removed for you. Use Load example to try a sample token.
- Read the header and payload on the right, and the issued, not-before and expiry times below them. The badge shows whether the token has expired.
- To check the signature of an HS256, HS384 or HS512 token, open the signature section, enter the secret and press Check signature.
Examples
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
→ Header {"alg":"HS256","typ":"JWT"}, payload {"sub":"1234567890","name":"John Doe","iat":1516239022}This is the sample token used by jwt.io. iat 1516239022 is 2018-01-18T01:30:22Z, and the token has no expiry claim.The same token with the secret your-256-bit-secret
→ Signature is valid for this secret.
The same token with the secret wrong
→ Signature does not match this secret.
How it works
The token is split at the dots. The header and the payload are decoded from Base64url into text and shown as formatted JSON, using the jose library. The third part is the signature and is not decoded.
The status badge compares the exp and nbf claims with the current time on your device: a token whose exp has passed is Expired, one whose nbf is still in the future is Not valid yet, one with a future exp is Not expired, and one without either claim has No expiry claim. The badge describes the claims only. It does not mean the token is genuine.
Signature checking recomputes the HMAC of the first two parts with the secret you enter, using the algorithm named in the header, and compares it with the signature. Only the signature is checked here; the expiry and other claims are not part of that result.
Sources
Frequently asked questions
- What is inside a JWT?
- A JWT is three parts separated by dots: a header that names the signing algorithm, a payload with claims such as the subject (sub), issuer (iss) and expiry (exp), and a signature. The first two are JSON written in Base64url.
- Is decoding the same as verifying?
- No. Decoding only reads the token, which anyone can do, because the payload is encoded and not encrypted. A token is trustworthy only after its signature has been verified with the right key, and its expiry and other claims have been checked, by your server.
- What do the time claims mean?
- exp is when the token stops being valid, nbf is the time before which it must not be accepted, and iat is when it was issued. All three are written in seconds since 1 January 1970 UTC. This tool shows them as dates and compares them with the current time to set the badge.
- Why can I only check HMAC signatures?
- HS256, HS384 and HS512 use one shared secret, so you can check them by entering that secret. Algorithms such as RS256 or ES256 need the issuer's public key, which this tool does not take.
- Is it safe to paste my token here?
- Decoding and checking run in your browser and nothing is sent anywhere. Still, a live token works like a password until it expires, so avoid pasting production tokens or secrets into websites you do not control, and prefer test tokens.