Decode and verify a JWT
Paste a JSON Web Token to see its header and claims, check expiry in plain dates, and verify HMAC signatures with your secret.
- Files never uploaded
- Free, no sign-up
- Works on any device
- Works offline
How to use the JWT decoder
Paste a token
Paste the JWT into the box.
Read the claims
See the header and payload, with exp, iat and nbf as real dates.
Verify (optional)
Enter the secret to check an HMAC signature.
About JWT decoder
Don’t paste production tokens into public sites
A JWT can contain user IDs, emails and permissions, and a live token can be replayed. This decoder works entirely offline in your browser.
Your files never leave your device
Most online PDF sites upload your documents to their servers. DocuVault doesn’t. Everything happens inside your browser, so there is nothing for anyone to see, store or leak.
Check it yourself
Use a tool once, then turn off your Wi-Fi or switch to airplane mode and use it again — it still works. Developers can watch the Network tab: no file is ever sent.
Step 1
You choose a file
Your browser opens it directly from your device — like opening it in an app.
Step 2
Your device does the work
The processing code runs inside this browser tab. No server ever receives your file.
Step 3
You save the result
The new file goes straight to your downloads. Close the tab and everything is gone.
Frequently asked questions
Is my token or secret sent anywhere?
No. Decoding and verification use your browser’s built-in crypto. Nothing is transmitted.
Can it verify RS256 tokens?
Not yet — verification currently supports HMAC (HS256, HS384, HS512). Decoding works for every algorithm.