The Volade Ecosystem — Web Tool

JWT Encoder / Decoder

Decode a JWT instantly: header, payload and signature shown as indented JSON with the claims identified, HS256 signature verification with a secret or RS256 / ES256 with a PEM public key, encoding and signing of a new token, expiry converted to readable dates. Free, no sign-up and 100% local: your token never leaves your browser.

6 processing modes0 byte sent to the server∞ tokens, no size limit
The tool

Your online JWT decoder

Paste a token, a header, a payload or a string taken from an Authorization header: decoding updates on every keystroke, with no « Convert » button.

JWT Encoder / Decoder

Online Development, Code & Data
Sign in
Shortcuts: Ctrl+Enter calculate
Ready.

                  

                  
The signature is not decrypted: it is checked with the secret or the public key in the « Verify » tab.
ClaimValueTypeRole
Decoding, verification and signing run as you type · Ctrl+Enter recalculates the active tab · native WebCrypto, no external library · 100% local, nothing leaves your device.
0,0 0Comment All tools
Free or Premium?

The JWT decoder is free and unlimited: no account, nothing to install, no network request. Premium unlocks the whole Volade ecosystem.

FreeReal-time decoding of header, payload and claims
FreeHMAC HS256 / HS384 / HS512 and PEM public key verification
FreeEncoding and signing of new tokens, expiry conversion
PremiumEncrypted cloud sync of history and snippets
PremiumAPI access and scripts shared across the ecosystem tools
Unlock Premium
Features

Decode, verify and encode a JWT, with no limits

One engine covers reading, integrity checking and token production — without ever leaving your device.

Decode header, payload and signature

Paste a token — even in uppercase, even with a Bearer prefix or quotes — and the header and payload appear as indented JSON while you type. Each claim is listed with its value, its type and its role, timestamps are converted to ISO 8601 and to time remaining, and the carried signature is displayed as-is.

Decode now

Verify a signature for real

The check is not cosmetic: the MAC is recalculated over the exact header.payload string, then compared to the signature in constant time. HS256, HS384 and HS512 use the shared secret; RS256, RS384, RS512, ES256, ES384 and PS512 use the PEM public key in SPKI format. The verdict is explicit: valid, invalid, or missing information.

Verify a signature

Complete privacy

No network request: decoding, verification and signing all run in your browser, even offline. Perfect for a production token, a staging key or a session token containing an identifier you would never hand to anyone — including the tool itself.

Learn more
How it works

Decode, verify or produce a token in three steps

No installation, no sign-up: the tool is always ready, on mobile as on desktop.

Paste the token

Grab the value after « Authorization: Bearer » or from your cookie, paste it into the « Decode » tab: the three segments are split and decoded immediately. A Bearer prefix, quotes or a line break are removed automatically.

Check the integrity

Switch to « Verify », pick the algorithm announced by the header, enter the secret or the public key: the tool recalculates the MAC and shows the verdict. This is the step everyone skips — and the only one that actually protects the content.

Produce a token

In « Encode », edit the payload, adjust exp and iat with the « Expiration » tab, sign with HS256: the token appears ready to copy. Local history keeps your latest tokens for one-click reload.

Quick reference

A JWT at a glance

What most developers check before reading a token — with the full anatomy in the « Anatomy & reference » tab.

SegmentRoleEncodingExample
1header (alg, typ)Base64URLeyJhbGciOiJIUzI1NiJ9
2payload (claims)Base64URLeyJzdWIiOiIxMjM0NTY3ODkwIn0
3signatureBase64URLSflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV…
expexpirationUnix (s)1793827200 → 2026-11-04
HS256HMAC + SHA-256shared secret32 bytes minimum
RS256RSA + SHA-256PEM public keyasymmetric verification
« + » in Base64—Base64URLreplaced by « - »
« / » in Base64—Base64URLreplaced by « _ »

What does « decode a JWT » mean?

Decode a JWT (« jwt decode », « decode jwt online ») means cutting the string at the dots, then decoding each segment from Base64URL to recover the original JSON. No key is needed: header and payload are simply encoded, not encrypted. That is exactly the intent behind « jwt payload decoder » or « decode jwt without verify » — see what the token contains, without pretending it is authentic.

Be sure to tell the two actions apart. Reading a JWT proves nothing: anyone can forge a token with an attractive payload and sign it with their own secret. Verify the signature proves the content was not modified by a third party. A decoder that shows « admin: true » without a signature check tells you a story, not a fact.

The three segments of a JWT

The string splits into exactly three dot-separated parts: header.payload.signature. The header contains at least alg and typ, sometimes kid to indicate which key was used. The payload carries the claims, these key-value pairs whose registry is maintained by the IANA. The signature covers the first two segments concatenated exactly as written — the slightest change to a space or a character breaks the comparison.

The whole difficulty is that these segments are Base64URL rather than Base64: the plus sign becomes a hyphen, the slash becomes an underscore, and the padding = disappears. A standard Base64 decoder will therefore fail on a valid JWT. The « Base64URL vs standard Base64 » table in the reference tab shows exactly these substitutions.

How to verify a signature: HS256, RS256, ES256

For an algorithm HMAC — HS256, HS384, HS512 — the same secret is used to sign and to verify: the tool recalculates HMAC(secret, base64url(header) + "." + base64url(payload)) and compares the result with the carried signature. This is the most common case, and also the most dangerous: any service holding the secret can issue a token. A secret under 32 bytes, reused across environments, is enough to compromise the whole chain.

For the algorithms asymmetric — RS256, RS384, RS512, ES256, ES384, ES512, PS256 — you only need the public key to verify, which lets you check a token issued by a third party without ever sharing its signing secret. Paste the key in PEM format -----BEGIN PUBLIC KEY----- (SPKI); the raw output of an OpenSSL export is directly usable. For ES256, the signature is in raw r||s format, the one WebCrypto expects.

Finally, watch out for thealg confusion : if your service expects RS256 but accepts a token whose header declares HS256, an attacker will sign with the public key — now an HMAC key — and pass verification. Pin the expected algorithm server-side, never read it from the token itself.

exp, iat, nbf: the timestamps that trip you up

These three claims are Unix seconds, with no milliseconds and no time zone: iat 1516239022 means 2018-01-17T21:30:22Z. Two mistakes keep coming back: comparing against a date in milliseconds (a value ten thousand times too large) and reading a timestamp as local rather than UTC. The « Expiration » tab converts both ways, showing ISO 8601, the local date and the time remaining or elapsed — enough to spot an « already expired » token down to the second.

Extending the lifetime does not raise security: a exp pushed-back value changes the displayed value, not the signature. If you must reissue, re-sign the token with the secret or the private key — that is exactly what the « Encode » tab is for.

Base64URL: why standard decoders fail

Base64URL (RFC 4648 §5) uses the alphabet A-Z a-z 0-9 - _ and allows no padding. A 20-character payload often produces a length that is not a multiple of four once the = : is normal, not corruption. The characters - and _ are ambiguous to the human eye, which explains half of the « broken tokens » reported. Our decoder accepts both alphabets, mixed case, optional padding and a Bearer.

Security: what a JWT does not do

A JWT gives you neither confidentiality nor revocation. The payload is readable by anyone: never put an email, an internal role or personal data you would not send in the clear. And a signed token stays valid until exp even after logout — you need a revocation list, some jti server-side tracking, or short lifetimes with a refresh token. Good practice: exp short (10 to 15 minutes), iat controlled, nbf aligned with iat, aud and iss verified on receipt.

Recommended for

Back-end and front-end developers (OAuth 2.0, OpenID Connect, REST APIs), integrators and DevOps (identity infrastructure, JWKS, key rotation), QA testers and pentesters (claim rewriting, alg confusion, expiration), system administrators (debugging an unexplained 401), students (understanding Base64URL and WebCrypto), and anyone who needs an online JWT decoder fast, complete and private — complemented by theBase64 encoder decoder, theURL encoder decoder and the JSON formatter.

FAQ

Frequently asked questions about the JWT decoder

Everything you want to know before decoding, verifying or signing a token.

How do I decode a JWT online?

Paste the token into the « Decode » tab: the header, payload and signature are split at first glance, then each Base64URL part is decoded into indented JSON. The standard claims (iss, sub, exp, iat, nbf, jti) are listed in a table with their type and role, and timestamps are shown in ISO 8601 with the time remaining or elapsed.

How do I verify a JWT signature?

In the « Verify » tab, pick the algorithm announced by the token. For HS256, HS384 and HS512, enter the shared secret: the tool recalculates the HMAC over the header.payload string and compares it with the carried signature. For RS256, RS384, RS512, ES256, ES384 and PS256, paste the PEM public key in SPKI format. The result shows « Signature valid » or « Signature invalid » with the reason.

Can I encode and sign a JWT here?

Yes. In the « Encode » tab, edit the JSON header and the JSON payload, pick the algorithm and enter the shared secret: the signed token appears instantly, ready to copy or download as jwt.txt. HS256, HS384, HS512 and none are supported for signing; the other algorithms are for verification.

What is a JWT and what are its three parts for?

A JWT (JSON Web Token) is a string of three dot-separated segments: the header declares the algorithm and type, the payload carries the claims, and the signature guarantees that nothing has been modified. The first two segments are JSON encoded in Base64URL — a transformation, not encryption: anyone can read them. Only the signature protects integrity.

How do I read the exp, iat and nbf claims?

exp, iat and nbf are Unix timestamps in seconds, not ISO dates. The « Decode » tab converts them automatically to ISO 8601 and to relative time (« expires in 2 d 03:00:00 »), and the « Expiration » tab converts both ways between a timestamp and a readable date, so you can check an apparently invalid token or craft an exact lifetime.

What is the difference between Base64 and Base64URL?

Base64URL replaces the plus sign with a hyphen and the slash with an underscore, then drops the « = » padding. It is mandatory in a JWT because a dot, a plus or a slash would break the split into three segments. It is also why some standard decoders fail on a payload that is perfectly valid.

Is a decoded JWT a password?

No. A JWT payload is simply Base64URL, so fully readable without any key: never put an identifier, an email, a role or a permission in it. The signature does not encrypt the content, it authenticates it. Keeping a secret on the client side requires separate symmetric encryption — a JWT is not built for that.

Does the tool send my token to a server?

No: decoding, verification and signing run in your browser with WebCrypto, with no network request and no account. That matters for a production token, which often contains a session identifier. History stays in your device's local storage and can be cleared in one click.

100% local JWT decoder: your token never leaves your computer

Unlike classic online JWT decoders, no string is transmitted: decoding, signature verification and encoding all run in your browser via WebCrypto, with no third-party library and no network request. That is what lets you inspect a real session token, a staging key or an internal service token safely, even offline or on a public network. History and your last input are kept locally (localStorage) and stay on your device.

The license Volade Premium adds optional, encrypted cloud sync independent of the tool — everything else stays free and unlimited, with no sign-up.

One premium license, all your web tools

JWT decoder, URL encoder decoder, Base64 encoder decoder, JSON formatter, generators, PDF editors and dozens of free tools — and the whole Volade ecosystem with a single license.

One licence, the whole premium ecosystem Browser · CMS · Desktop · Mobile · Scripts · API · Tools · Database
One licence, the whole ecosystem Go premium Log in