Generate (HMAC signing) and parse (decode + verify) JSON Web Tokens
Once a secret is provided, the tool recomputes the HMAC over the first two parts using the algorithm from the Header (alg) and compares it with the third part to detect tampering.
{
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "1234567890",
"name": "刚人",
"iat": 1516239022
}
}Decode the Header, Payload and signature of a JWT (JSON Web Token) to help debug auth flows.
A JWT is three Base64Url segments—header.payload.signature—joined by dots.
Paste a token to view its plaintext; no key required.
This tool parses entirely in your browser and never uploads the token to any server.
The payload is not encrypted by default—never store passwords or other sensitive data in a token.