JWT Tool

Generate (HMAC signing) and parse (decode + verify) JSON Web Tokens

Docs

Valid JWT · Header / Payload decoded
JWT token
Secret (optional, used to verify)

Once a secret is provided, the tool recomputes the HMAC over the first two parts using the algorithm from the Header (alg) and compares it with the third part to detect tampering.

Decoded result
No secret · decode only
{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sub": "1234567890",
    "name": "刚人",
    "iat": 1516239022
  }
}

使用说明

Decode the Header, Payload and signature of a JWT (JSON Web Token) to help debug auth flows.

Structure

A JWT is three Base64Url segments—header.payload.signature—joined by dots.

Decode

Paste a token to view its plaintext; no key required.

Local only

This tool parses entirely in your browser and never uploads the token to any server.

Note

The payload is not encrypted by default—never store passwords or other sensitive data in a token.