JWT Debugger & Encoder / Decoder
Decode, verify, and generate JSON Web Tokens (JWT) in real-time with color-coded breakdown, claim timestamps, and HMAC SHA-256 signature verification.
- Paste a JWT to instantly decode its header and payload with a color-coded breakdown.
- Standard claims like exp, iat, and nbf are shown as readable timestamps.
- Enter a secret to verify an HS256 signature, or edit the payload and re-sign to generate a new token.
- Use the quick-inject buttons to add standard claims while building a test token.
All processing happens entirely in your browser. Your data never leaves your device.
Key Features
- Decode JWT header and payload with color-coded breakdown
- Automatic timestamp conversion for exp, iat, nbf claims
- HS256 signature verification with secret key input
- Token generation — edit payload and re-sign with your secret
- Quick-inject buttons for standard claims (exp, iat, sub, iss, etc.)
- Token expiration status indicator (valid, expired, not-yet-valid)
- 100% client-side — your tokens and secrets never leave your browser
About JWT Debugger
JSON Web Tokens (JWT) are an open standard (RFC 7519) for securely transmitting claims between parties as a compact, URL-safe JSON object. They are the dominant authentication mechanism in modern web applications, used for stateless session management, API authorization (Bearer tokens), single sign-on (SSO), and microservice-to-microservice communication.
A JWT consists of three Base64URL-encoded parts separated by dots: a header (algorithm and token type), a payload (claims like user ID, expiration time, and roles), and a signature (cryptographic proof that the token hasn't been tampered with). The most common signing algorithm is HMAC SHA-256 (HS256).
ForgeKit's JWT Debugger decodes any JWT into its three components with color-coded syntax highlighting. Standard claims like exp (expiration), iat (issued at), and nbf (not before) are automatically converted from Unix timestamps to human-readable dates. You can also verify HS256 signatures with a secret key, edit payloads to generate new tokens, and use quick-inject buttons to add standard claims.
Frequently Asked Questions
Yes. This tool runs entirely in your browser. Your token is never sent to any server, logged, or stored. However, avoid sharing JWTs from production systems in any public tool.
HS256 (HMAC-SHA256) is a symmetric signing algorithm. The same secret key is used to both sign and verify the token. It's the most common JWT algorithm for single-server applications.
Currently, the tool supports HS256 (symmetric) signature verification. RS256 (asymmetric, using RSA public/private keys) verification is not supported in this version.
The exp (expiration) claim is a Unix timestamp. After this time, the token should be rejected by the server. The debugger shows whether the token is currently valid, expired, or not-yet-valid.
The signature prevents tampering. If anyone modifies the header or payload, the signature will no longer match, and the token will fail verification. However, the payload is only Base64-encoded (not encrypted), so it can be read by anyone.