Token Input
Client-side only. Do not paste production secrets into shared machines.
Decoded JSON
Decode is not verification. Use the signature panel before trusting claims.
Header
Payload
HS Signature Verification
Supports HS256, HS384 and HS512 with a pasted shared secret. RS, ES and EdDSA need public key verification in your app.
Local HS256 Test Token Generator
For local development only. It signs in the browser with the secret you enter.