JWT Decoder - SimeonOnSecurity
NOTE: This tool runs entirely in your browser with client-side JavaScript. A token you paste is never transmitted, logged, or stored. It is split and decoded locally on this page.
WARNING: Decoding is not verification. This tool reads a token without checking its signature, so a decoded token proves nothing about who issued it or whether it was altered. Never treat a token as trusted because it decoded cleanly, and never paste a production token into a page you do not control.
Header
Paste a token to see its header.
Payload
Paste a token to see its payload.
Registered Claims
| Time and identity claims such as exp, iat, nbf, iss and sub appear here. |
What to Check by Hand
- Algorithm. If the header says
none, any signature check that trusts the header is broken. - Expiry. Confirm
expis in the future and that the service actually enforces it. - Audience. A token minted for one service should not be accepted by another through
aud. - Signature. Verifying it needs the key, which this page deliberately does not have.
Sponsored by The Cyber Sentinels Club
