JWT Decoder & HMAC Signature Verifier

Decode a JWT header and payload locally. Optionally verify HS256, HS384, or HS512 with a secret.

How it works
  • Optional verification covers HMAC algorithms only (HS256, HS384, HS512). Treat claims as untrusted until your server verifies them for production use.

Leave empty to decode only. HS256, HS384, and HS512 only.

About JWT decoding & verification

What is a JSON Web Token?

A JSON Web Token (RFC 7519) is a compact, URL-safe means of transferring claims between two parties. Tokens consist of three Base64URL-encoded parts separated by dots: header, payload, and cryptographic signature.

Decoding extracts the header and claims into readable JSON. Verification recalculates the HMAC signature using a shared secret and validates exp (expiration), iat (issued-at), and nbf (not-before) timestamps. Work executes locally in Web Crypto; secrets and tokens are never transmitted.

Decode and verify JWT in code

JavaScript (Node.js)
const crypto = require("crypto");
const [header, payload, signature] = token.split(".");
const expected = crypto.createHmac("sha256", secret)
  .update(`${header}.${payload}`)
  .digest("base64url");
const isValid = crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected));
Python
import hmac, hashlib, base64
header, payload, sig = token.split(".")
expected = base64.urlsafe_b64encode(
    hmac.new(secret.encode(), f"{header}.{payload}".encode(), hashlib.sha256).digest()
).decode().rstrip("=")
is_valid = hmac.compare_digest(sig, expected)

JWT decoding FAQ

What is the difference between decoding and verification?
Decoding simply parses the Base64URL segments to read the JSON payload without validating the authenticity. Verification uses cryptographic hashing with a secret key to confirm the token has not been tampered with.
Which algorithms can this tool verify?
This tool supports symmetric HMAC algorithms: HS256, HS384, and HS512. Asymmetric algorithms (RS256, ES256) require public/private key pairs and can be decoded but not signed locally here.
Is it safe to paste production tokens?
Yes. ToolingO runs 100% locally in your browser. Neither tokens nor secrets are logged, sent to servers, or included in analytics.