JWT Tools

Decode, edit, sign and verify JWTs locally in your browser.

Runs locally in your browser. Your input is not uploaded or saved.

Decoding does not verify a signature. Use optional signature verification below to check a token against a shared secret.

Bearer, JWT, Token and other single-word prefixes are removed on paste.

Optional signature verification

HMAC algorithms only. RSA/ECDSA keys are not supported. The secret is used as text, not decoded from Base64. Signature verification does not validate issuer, audience, expiration or other claims.

Signature not verified.

Also useful