Free tools

JWT decoder.

Decode a JSON Web Token's header and payload, and flag risky algorithms and claims. The token never leaves your browser.

Decoded in your browser. The token is never sent anywhere. Even so, do not paste live production tokens into any website.

What it checks

Checks

  • The header and the payload, decoded.

  • The algorithm: none, shared-secret (HS) or public-key.

  • exp, nbf and iat as dates, and a token that never expires or lives for weeks.

  • Headers that let a token choose its own key (jku, x5u, jwk), and a suspicious kid.

  • A Supabase service_role token, and claims that look sensitive.

Doesn’t check

  • The signature. Decoding is not verifying: anyone can make a token that decodes.

  • Whether the server that accepts the token checks it properly.

  • Encrypted tokens (JWE).

Questions

Is my token sent anywhere?

No. Decoding happens in this page's JavaScript, and nothing you paste is sent to LaunchSafe or anyone else.

Does it verify the signature?

No. Verifying needs the key, which should never be pasted into a website.

Why is alg none dangerous?

A token with alg none has no signature, so anyone can write one. A server that accepts it lets anyone sign in as anyone.

How long should a token last?

Access tokens usually last minutes to an hour. Longer sessions are better handled with a refresh token that can be revoked.

Check a whole repository,
free.