JWT Utility

Signature / Signing Key

Select an algorithm and provide the key used to sign this JWT.

JWTs are encoded, not encrypted. Do not put secrets in the payload.

FAQ: JWT Utility

  1. A JSON Web Token is a compact signed token commonly used to pass claims between services, APIs, and browser applications.
  2. JWTs have three dot-separated parts: header, payload, and signature, usually shown as xxxxx.yyyyy.zzzzz.
  3. The header describes the token type and signing algorithm, the payload contains claims, and the signature proves whether the token matches the key used to sign it.
  4. This utility can encode new JWTs, decode existing JWTs, inspect header and payload JSON, and show claims in a readable table view.
  5. Signature verification can check whether a token is valid when you provide the matching secret or public key.
  6. Commonly used algorithms include HS256, HS384, HS512, RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384, ES512, and EdDSA.
  7. HMAC algorithms use a shared secret, while RSA, RSA-PSS, ECDSA, and EdDSA workflows use private keys for signing and public keys for verification.
  8. Use this tool to debug authentication headers, inspect API tokens, review expiration and issued-at claims, or verify test tokens during development.
  9. The encoder is useful for generating sample tokens when testing backend auth flows, frontend guards, or API client integrations.
  10. All decoding, encoding, and verification work runs in your browser, helping you inspect sensitive tokens without uploading them to a server.

If you want to report any bug or place a feature request, feel free to send Feedback or drop us an email at rgstudiobd@gmail.com