thoughtasylumTOOLBOX Preview

Tools › Encoding

JWT Decoder & Encoder

A token's header and payload, with its times in local time and its lifetime. Check its signature with a secret, a public key or a JWK set, make and sign a new token, or convert keys between JWK and PEM.

About this tool What it's for, how to use it and an example

What it's for

Look inside a JSON Web Token (JWT): the long eyJ… strings that APIs and single sign-on systems hand out to prove who you are. Handy for checking who a token was issued to, what it grants, and whether it’s still valid. It can also check a token’s signature, and make and sign a token of your own for testing.

For example, when an API call starts failing with 401 Unauthorized, paste the token from the request to see whether it has expired, or was issued for a different audience (aud) or with the wrong scopes.

How to use it

Paste the token into the box. A leading Bearer is ignored, so you can paste the whole Authorization header value. The header and payload appear as formatted JSON, and the issued (iat), valid-from (nbf) and expiry (exp) times are shown in your local time, with how long ago or how far away each one is, and the token’s lifetime with how much of it has gone.

To check the signature, paste the shared secret (for HS256, HS384 and HS512) or the public key in PEM form, starting -----BEGIN PUBLIC KEY----- (for RS, PS and ES tokens), under “Check the signature”. It reports a valid or invalid signature, or that the key doesn’t suit the token’s algorithm. A public key in JWK form, or a whole JWK set as an identity provider publishes it at its jwks_uri, works too: the key is picked by the token’s kid.

Convert a key between JWK and PEM turns a JWK into a PEM key and a PEM key into a JWK, for RSA, EC (P-256, P-384 and P-521) and Ed25519 keys, public or private.

To make a token, pick an algorithm, edit the header and payload, and enter the secret or the PEM private key (-----BEGIN PRIVATE KEY-----, the PKCS#8 form) for the algorithm. “Set iat to now” and “Set exp to 1 hour from now” add those claims to the payload. Press Sign, then Copy.

Example

Paste this token:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJhbGljZSIsImF1ZCI6ImFwaS5leGFtcGxlLmNvbSIsInNjb3BlIjoicmVhZCIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MjI5MjAwfQ.c2lnbmF0dXJl

The payload shows it was issued to alice for api.example.com with read scope. It was issued at midnight UTC on 1 January 2026 and expired an hour later, so the tool reports “This token has expired.” Enter secret as the key and it reports an invalid signature, since that signature was made up.

Good to know

A token that decodes cleanly isn’t necessarily genuine: only a valid signature from the right key shows that. A token with the algorithm none is unsigned and is never reported as valid. Only the HS, RS, PS and ES algorithms with 256, 384 and 512-bit hashes are supported. Keys and secrets are never saved or put in a shared link, but treat real tokens and keys like passwords and be careful where else you paste them.

Guide: What's inside this JWT?

Header


      

Payload


      

Check the signature

Convert a key between JWK and PEM

Create a token

Keys and secrets stay on this page: they are not saved or put in links.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close