Always verify signatures
Decode to inspect, but never trust claims until you validate the signature with the issuer's secret or public key.
Paste a JSON Web Token to inspect its header and payload locally, validate its structure, then verify HMAC signatures when you have the secret.
Paste a token and secret to verify.
Decoding only reveals claims. Trust the token only after a valid signature and expiration check.
JSON Web Tokens package authentication claims into a compact string separated by dots. Each segment is Base64URL encoded, which is why you can decode the header and payload without hitting external services.
| Segment | Contains | Example claims | Security notes |
|---|---|---|---|
| Header | Algorithm (`alg`) and token type (`typ`). | {"alg":"HS256","typ":"JWT"} |
Never accept "alg":"none" in production. |
| Payload | Claims about the subject, issuer, scopes. | {"sub":"123","exp":1700000000} |
Visible to anyone with the token. Do not store secrets here. |
| Signature | HMAC or asymmetric signature over header+payload. | HMACSHA256(base64Url(header).base64Url(payload), secret) |
Required to verify authenticity. Use the verifier above for HMAC-signed tokens. |
Decoding claims is only the first step. Use these guidelines to keep tokens safe and your APIs predictable.
Decode to inspect, but never trust claims until you validate the signature with the issuer's secret or public key.
Reject expired tokens and ensure aud/iss claims match your application to prevent replay across
services.
Anyone who obtains the JWT can read payload data. Store secrets server-side or encrypt the token with JWE when necessary.
Decode inspects public header and payload fields. Verify checks an HMAC signature only when you supply the matching secret.
A valid signature does not by itself authorize a request. RS256, ES256 and encrypted JWE are outside this verifier. Never treat decoded claims as trusted before verification.
JWT specification: RFC 7519A JWT contains a header, payload, and signature separated by dots. The header defines the algorithm, the payload carries claims, and the signature proves authenticity when verified with the correct key.
No. Decoding only reveals the Base64URL-encoded JSON. Use the verifier with the issuer secret before you trust any claim in the payload.
Tokens can leak sensitive information and be replayed if you skip expiration or revocation checks. Avoid logging JWTs and
refuse tokens signed with weak secrets or the none algorithm.
No. The decoder targets signed JWTs (JWS). Encrypted JWEs require the decryption key and algorithms that are outside the scope of this page.
No. HashyTools processes JWTs entirely on your device so your secrets and claims remain private.
Protect text with AES-GCM and PBKDF2 tokens that stay on-device.
Generate MD5, SHA-1, and SHA-256 digests locally with Web Workers.
Convert any text to or from Base64 without leaving your browser.
Validate, format, and diff JSON without network calls.
Format, minify and inspect XML locally with tree view and JSON conversion.
Experiment with regular expressions and capture groups locally.
Encode components and inspect query parameters locally.
Create collision-resistant UUID v4 identifiers using Web Crypto.
Build strong passwords with custom length, charset, and entropy.
Translate Unix timestamps into readable dates and back again.
Convert case, slugify, and clean strings on-device.
Switch between HEX, RGB, HSL, and Tailwind palettes instantly.
Design QR codes for text, Wi-Fi, contacts, email, or SMS locally.
Generate EAN and Code 128 barcodes and download crisp PNG output.
Look up your public IP using disclosed external services.
Produce paragraphs, lists, and markdown filler text fast.
Run the AES interoperability guide or read how these tools are checked.