JSON Web Token (JWT) DebuggerRFC 7519
Decode, inspect, verify, and re-sign JWT headers, payloads, and claims with local secret or public key. All operations execute directly in your browser with zero network requests.
Encoded Token
Changes to the Header or Payload on the right automatically update the encoded token on the left. If an HMAC secret is set, it will automatically re-sign the token with the algorithm specified in the header.
| Claim Key | Claim Meaning | Category | Decoded Value |
|---|---|---|---|
| No claims found in payload. | |||
Comprehensive Guide to JSON Web Tokens (JWT) & Signature Verification
Everything you need to know about RFC 7519, Base64URL encoding, cryptographic hashing, and safe client-side debugging.
The Header consists of two essential claims: the token type (typ, normally "JWT") and the cryptographic algorithm (alg, such as HS256, RS256, or ES256). Optionally, a Key ID (kid) is provided for key rotation.
The Payload stores authorization claims and identity details. Standard claims defined by RFC 7519 include iss (Issuer), sub (Subject), exp (Expiration), and iat (Issued At).
To generate the signature, the encoded header and payload are concatenated with a period and signed using a cryptographic secret or private key: Algorithm(base64Url(header) + '.' + base64Url(payload), secret).
Symmetric (HMAC) vs Asymmetric (RSA/ECDSA) Verification
| Algorithm Family | Signing Key | Verification Key | Primary Use Case |
|---|---|---|---|
| HS256 / HS384 / HS512 | Shared Secret (Symmetric) | Same Shared Secret | Single service, internal microservices where all nodes trust the secret. |
| RS256 / RS384 / RS512 | Private Key (RSA PKCS#8) | Public Key (SPKI PEM / JWK) | OAuth 2.0 / OpenID Connect, Auth0, Okta, Firebase, AWS Cognito. |
| ES256 / ES384 / ES512 | Private Key (ECDSA) | Public Key (ECDSA P-256) | High performance mobile & edge authentication with smaller signatures. |
Critical Security Pitfalls to Avoid
- The `alg: none` Vulnerability: Attackers may strip the signature and alter the algorithm header to 'none'. Production APIs must explicitly whitelist accepted algorithms.
- Sensitive Data in Payloads: JWT payloads are Base64URL encoded, NOT encrypted. Never include passwords, social security numbers, or internal API keys.
- Weak HMAC Secrets: Short secrets like 'secret123' can be cracked in seconds using offline dictionary attacks. Use cryptographically random 256-bit keys.
Why 100% Client-Side Privacy Matters
Many online JWT decoders send tokens to remote servers for logging or telemetry. If a developer pastes a production token or API secret into a remote tool, sensitive access tokens and session credentials could be intercepted.
This debugger operates strictly inside your browser tab using the native Web Cryptography API. You can safely disconnect your internet connection and inspect, debug, and verify tokens in full offline isolation.