JWT Decoder & HS256 Verifier
Built for developers, this tool runs 100% locally in your browser, using the Web Crypto API for HMAC verification. Your token and secret never leave your device.
Result
FAQ
Q: Why can I decode any JWT without a secret, but verifying needs one?
A: A JWT's header and payload are just Base64url-encoded JSON — anyone can read them without any key, which is why you should never put secret data in a JWT payload. Verifying the signature is different: it proves the token wasn't tampered with, which requires the same secret (for HS256) that was used to sign it.
Q: Why does this tool only support verifying HS256 signatures?
A: HS256 uses a single shared secret for both signing and verifying, which the Web Crypto API's HMAC support handles well in the browser. RS256/ES256 use asymmetric key pairs and require importing a PEM-formatted public key, which is significantly more complex to expose in a simple form — that support may be added later.