Webhook HMAC Signer
Sign and verify GitHub, Stripe, and Slack webhook signatures locally.
OpenDecode JWT tokens. - runs entirely in your browser. Free, fast and private.
Paste the three-part base64url token string.
Header and claims decode to readable JSON objects.
Expiry and issued-at timestamps show in local time.
Copy decoded payload for debugging auth flows.
A support ticket says "token expired" but the clock on the claim does not match what you expect. JWT Decoder splits header and payload into readable JSON and turns iat, nbf, and exp into local timestamps.
Decode when you need to inspect alg, kid, roles, tenant IDs, or expiry without calling the issuer. This page does not prove the signature is valid. Decoding only Base64URL-parses the parts. For HS256 checks, use JWT Verify with the shared secret on the same device.
Pitfall: treating a decoded payload as trusted input. Anyone can mint an unsigned-looking JWT string. Always verify signatures in production code paths.
Tip: clear the textarea when you finish if the token is a production session JWT, not a fixture.
Tokens are parsed with browser APIs in this tab. Clear the field when you are done so the JWT is not left on a shared screen.
Processes data instantly with no server round-trips.
Your data never leaves your browser. Nothing is uploaded.
Works in any modern browser. Nothing to download or install.
No limits, no sign-up, no credit card required.
Works on desktop, tablet and mobile devices.
Beautiful in both themes. Your preference is saved.
Keyboard shortcut
See claims and expiry without guessing from opaque strings.
Confirm exp/iat against local time when users report lockouts.
Inspect header alg, then move to JWT Verify for HS256.
Answers for this tool. For site-wide help, open the FAQ hub.
No. Decoding reads claims; use JWT Verify to check signatures.
JWT Decoder Decode JWT tokens. It runs entirely in your browser with instant feedback.
No server upload is required for formatting/validation. Clearing the page removes the text from memory.
Validators report problems; formatters beautify valid structure. Severely broken input may need manual fixes first.
Formatters and converters aim to preserve meaning. Always review diffs for mission-critical code before committing.
Paste smaller chunks if the tab slows down. Minifiers and deep validators scale with input size on the CPU you have.
Many tools support Ctrl/⌘+Enter to run and standard copy shortcuts. Check the tool toolbar for Sample / Clear / Download.
When options exist (spaces vs tabs, indent width), set them before copying output into your repo to match project style.
After the page loads, formatting continues offline. CDN libraries need an initial network load.
Bookmark JWT Decoder, copy output into editors, or chain steps with Recipes.