JWT Utility
Signature / Signing Key
Select an algorithm and provide the key used to sign this JWT.
JWTs are encoded, not encrypted. Do not put secrets in the payload.
FAQ: JWT Utility
- A JSON Web Token is a compact signed token commonly used to pass claims between services, APIs, and browser applications.
- JWTs have three dot-separated parts: header, payload, and signature, usually shown as
xxxxx.yyyyy.zzzzz. - The header describes the token type and signing algorithm, the payload contains claims, and the signature proves whether the token matches the key used to sign it.
- This utility can encode new JWTs, decode existing JWTs, inspect header and payload JSON, and show claims in a readable table view.
- Signature verification can check whether a token is valid when you provide the matching secret or public key.
- Commonly used algorithms include HS256, HS384, HS512, RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384, ES512, and EdDSA.
- HMAC algorithms use a shared secret, while RSA, RSA-PSS, ECDSA, and EdDSA workflows use private keys for signing and public keys for verification.
- Use this tool to debug authentication headers, inspect API tokens, review expiration and issued-at claims, or verify test tokens during development.
- The encoder is useful for generating sample tokens when testing backend auth flows, frontend guards, or API client integrations.
- All decoding, encoding, and verification work runs in your browser, helping you inspect sensitive tokens without uploading them to a server.
If you want to report any bug or place a feature request, feel free to send Feedback or drop us an email at rgstudiobd@gmail.com
