It looks like your browser language isn't English. Would you like to switch to the Traditional Chinese version? 切換到繁體中文 ×

JWT Decoder & HS256 Verifier

security Security & Privacy Guarantee

Built for developers, this tool runs 100% locally in your browser, using the Web Crypto API for HMAC verification. Your token and secret never leave your device.

Result

Waiting for input...

FAQ

Q: Why can I decode any JWT without a secret, but verifying needs one?

A: A JWT's header and payload are just Base64url-encoded JSON — anyone can read them without any key, which is why you should never put secret data in a JWT payload. Verifying the signature is different: it proves the token wasn't tampered with, which requires the same secret (for HS256) that was used to sign it.

Q: Why does this tool only support verifying HS256 signatures?

A: HS256 uses a single shared secret for both signing and verifying, which the Web Crypto API's HMAC support handles well in the browser. RS256/ES256 use asymmetric key pairs and require importing a PEM-formatted public key, which is significantly more complex to expose in a simple form — that support may be added later.

Done