Back to Tools

JWT Debugger & Signature Verifier

100% Client-Side Private

JSON Web Token (JWT) DebuggerRFC 7519

Decode, inspect, verify, and re-sign JWT headers, payloads, and claims with local secret or public key. All operations execute directly in your browser with zero network requests.

Encoded Token

0 chars
HeaderPayloadSignature
Instant 2-way sync
Alg: UNKNOWN
How editing works

Changes to the Header or Payload on the right automatically update the encoded token on the left. If an HMAC secret is set, it will automatically re-sign the token with the algorithm specified in the header.

HeaderAlgorithm & Token Type
PayloadData & Claims
Quick Add:
SignatureCryptographic Verification & Key
UNKNOWN • Secret
Provide key or secret below to verify token integrity.
Claim KeyClaim MeaningCategoryDecoded Value
No claims found in payload.

Comprehensive Guide to JSON Web Tokens (JWT) & Signature Verification

Everything you need to know about RFC 7519, Base64URL encoding, cryptographic hashing, and safe client-side debugging.

1. Header (JOSE)

The Header consists of two essential claims: the token type (typ, normally "JWT") and the cryptographic algorithm (alg, such as HS256, RS256, or ES256). Optionally, a Key ID (kid) is provided for key rotation.

2. Payload (Claims)

The Payload stores authorization claims and identity details. Standard claims defined by RFC 7519 include iss (Issuer), sub (Subject), exp (Expiration), and iat (Issued At).

3. Signature

To generate the signature, the encoded header and payload are concatenated with a period and signed using a cryptographic secret or private key: Algorithm(base64Url(header) + '.' + base64Url(payload), secret).

Symmetric (HMAC) vs Asymmetric (RSA/ECDSA) Verification

Algorithm FamilySigning KeyVerification KeyPrimary Use Case
HS256 / HS384 / HS512Shared Secret (Symmetric)Same Shared SecretSingle service, internal microservices where all nodes trust the secret.
RS256 / RS384 / RS512Private Key (RSA PKCS#8)Public Key (SPKI PEM / JWK)OAuth 2.0 / OpenID Connect, Auth0, Okta, Firebase, AWS Cognito.
ES256 / ES384 / ES512Private Key (ECDSA)Public Key (ECDSA P-256)High performance mobile & edge authentication with smaller signatures.

Critical Security Pitfalls to Avoid

  • The `alg: none` Vulnerability: Attackers may strip the signature and alter the algorithm header to 'none'. Production APIs must explicitly whitelist accepted algorithms.
  • Sensitive Data in Payloads: JWT payloads are Base64URL encoded, NOT encrypted. Never include passwords, social security numbers, or internal API keys.
  • Weak HMAC Secrets: Short secrets like 'secret123' can be cracked in seconds using offline dictionary attacks. Use cryptographically random 256-bit keys.

Why 100% Client-Side Privacy Matters

Many online JWT decoders send tokens to remote servers for logging or telemetry. If a developer pastes a production token or API secret into a remote tool, sensitive access tokens and session credentials could be intercepted.

This debugger operates strictly inside your browser tab using the native Web Cryptography API. You can safely disconnect your internet connection and inspect, debug, and verify tokens in full offline isolation.