---
title: "JWT Decoder — Decode, Verify, and Generate"
description: "Decode, verify, and generate JSON Web Tokens in your browser: HMAC HS256/384/512 and RS256 with a PEM key. Secrets stay on this page. The API decodes and signs HMAC test tokens; it does not verify."
url: https://findutils.com/developers/jwt-decoder/
category: developers
---

# JWT Decoder — Decode, Verify, and Generate

Decode, verify, and generate JSON Web Tokens in your browser: HMAC HS256/384/512 and RS256 with a PEM key. Secrets stay on this page. The API decodes and signs HMAC test tokens; it does not verify.

**Use this tool:** [JWT Decoder — Decode, Verify, and Generate](https://findutils.com/developers/jwt-decoder/)

## Programmatic access

- REST id `jwt-decode`: POST https://api.findutils.com/api/tools/jwt-decode/execute (reference: https://findutils.com/api/jwt-decode/)
- MCP tool `jwt_decode` on https://mcp.findutils.com (reference: https://findutils.com/mcp/jwt-decode/)

## Why use this JWT decoder?

Decode a JSON Web Token, verify its signature with an HMAC secret or RSA public key, and generate HS256, HS384, HS512, or RS256 tokens. Expiration claims display as ISO 8601 timestamps. Signature stays unverified until you run Verify. All of this runs in your browser.

## Tips for Working with JWTs

- Never share a valid JWT publicly. Even though the payload is only Base64URL-encoded (not encrypted), a valid signature lets anyone use the token until it expires.
- Check the exp claim first when debugging. This decoder converts the Unix timestamp to ISO 8601 so you can see whether the token is expired.
- Use short expiration times for access tokens (5 to 15 minutes) and longer lifetimes for refresh tokens. Generate both and inspect the exp values.
- The alg field in the header should never be none in production. This page fails verify for none even if you paste a secret.
- Verify RS256 with the public key, not the HMAC secret. Do not treat a PEM file as an HMAC secret.

## Frequently Asked Questions

### What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe token format used for transmitting information between parties. It consists of three parts: header, payload, and signature, each separated by a dot and encoded in Base64URL format.

### Is my token secure when using this tool?

Decoding, signature verify, and signing run in your browser. The token, HMAC secret, and PEM key are not sent to a server and are not logged. You can disconnect from the network after the page loads and still use the tool.

### Can this tool verify JWT signatures?

Yes. Open the Verify tab. HS256, HS384, and HS512 use an HMAC secret. RS256 uses an SPKI public key or a PKCS8 private key in PEM form. The check uses Web Crypto in the browser. Algorithm none always fails, even if a secret is present.

### What do the common JWT claims mean?

Registered claims include sub (subject identifier), iat (issued at timestamp), exp (expiration timestamp), nbf (not before), iss (token issuer), aud (intended audience), and jti (unique token ID). Custom claims can contain any application-specific data.

### Why are some timestamps shown as ISO dates?

Standard JWT timestamp claims like iat, exp, and nbf are stored as Unix epoch seconds. This tool converts those fields to ISO 8601 so you can see the exact expiration without a timezone guess from the local clock display.

### What does the alg field in the header mean?

The alg field specifies the cryptographic algorithm used to sign the token. This page verifies HS256, HS384, HS512, and RS256. The algorithm none means the token is unsigned and never verifies as valid on this page.

### Can I decode an expired JWT?

Yes. Expiration only affects whether a server should accept the token. The decoder reads any structurally valid JWT and flags expired when exp is in the past. You can still run Verify on an expired token.

### What is the difference between decoding and decrypting a JWT?

Decoding a JWT means Base64URL-decoding the header and payload, which does not require a key. Decrypting applies to JWE tokens where the payload is encrypted. This tool handles standard signed JWTs (JWS), not encrypted JWE tokens.

### How do I know if my JWT has been tampered with?

Open the Verify tab and supply the HMAC secret or RSA public key that the issuer used. If the signature does not match the header and payload bytes, the token was altered or the key is wrong. Decode alone cannot detect tampering.

### What is the maximum size a JWT can be?

This page rejects tokens larger than 32 KB and keys larger than 16 KB. Tokens are typically sent in HTTP headers, which most servers cap at 8 KB. Keep payloads small and store only essential claims.

### Can I decode, verify, or generate JWTs through the FindUtils API?

Partly. The REST and MCP tool jwt-decode decodes the header and payload and does not verify the signature. jwt-generator signs HMAC (HS256, HS384, HS512) test tokens, and jwt-security-validator checks the algorithm and time claims. Signature verification and RS256 signing run only on this page, in your browser, so you never send a secret or private key to the API.

## Related Tools

- [JWT Generator](https://findutils.com/security/jwt-generator/)
- [JWT Security Validator](https://findutils.com/security/jwt-security-validator/)
- [JSON Formatter](https://findutils.com/developers/json-formatter/)
- [Base64 Encoder](https://findutils.com/developers/base64-encoder/)
- [Unix Timestamp](https://findutils.com/developers/unix-timestamp/)
- [JSON to TypeScript](https://findutils.com/developers/json-to-typescript/)
- [Hash Comparison Tool](https://findutils.com/security/hash-comparison-tool/)
- [URL Encoder/Decoder](https://findutils.com/network/url-encoder-decoder/)
