What this tool checks
- Header: algorithm (alg), type and key ID (kid)
- Payload: every claim
- exp, iat, nbf dates and time remaining
- Risky settings such as “alg: none” and tokens without expiry
- HMAC (HS256/384/512) signature verification
How to use it
- 01
Paste the token (it starts with eyJ…).
- 02
Header and payload decode instantly.
- 03
For HS* tokens, enter the secret to verify the signature.
Technical details
Decoding is not verifying
A JWT's header and payload are only Base64URL-encoded; anyone can read them. Security depends on the server verifying the signature with the right key and algorithm.
Common mistakes
Accepting “alg: none”, trusting the algorithm from the token itself, weak HMAC secrets, long-lived tokens without exp and sensitive data in the payload are the findings we see most.
Privacy
The token and secret stay in your browser; verification runs locally with the Web Crypto API. Still, avoid sharing production tokens.
Frequently asked questions
Is the payload encrypted?
No. Standard JWT (JWS) content is only encoded. Use JWE for data that must stay secret, or keep it out of the token.
Can I verify RS256 or ES256 tokens?
This tool currently verifies HMAC (HS*) signatures only. Asymmetric signatures need the issuer's public key (JWKS).
How long should a token live?
Short lifetimes for access tokens — minutes — plus separate, revocable refresh tokens are recommended.
Why is “alg: none” dangerous?
It means an unsigned token. If the server accepts it, anyone can mint tokens for any user or role.