Is it safe to paste a production token here?
The token is decoded in this tab and never sent anywhere. Still, a valid token is a credential: treat it like a password, and prefer expired or test tokens when debugging.
Can a JWT be decoded without the secret?
Yes. The header and payload are only Base64URL-encoded, not encrypted, so anyone holding the token can read them. The secret or key is needed only to create or verify the signature.
Why doesn't this verify the signature?
Verification needs the issuer's secret or public key and belongs on your server, using a maintained JWT library. A browser tool that asks for your signing secret would be a security risk.
How do I check if a JWT has expired?
Paste it here and look at the status badge and the Expires row. Programmatically, compare the exp claim (seconds since 1970) with the current Unix time in seconds, allowing a small leeway for clock skew.
What is the difference between HS256 and RS256?
HS256 uses one shared secret to both sign and verify, so every verifier could also mint tokens. RS256 signs with a private key and verifies with a public key, so APIs can check tokens without being able to create them.
What does alg: none mean?
It marks an unsigned token. Servers should reject it unless they explicitly expect unsigned tokens, which is almost never the case.
Why is my token's expiry date thousands of years away?
The issuer stored exp in milliseconds instead of seconds. JWT time claims are NumericDates in seconds, so divide by 1000 when creating them.
Can it decode encrypted tokens (JWE)?
No. A JWE has five parts and its payload is encrypted, so it cannot be read without the decryption key. The tool recognises the format and tells you.
Should I store JWTs in localStorage or cookies?
An HttpOnly, Secure, SameSite cookie is safer in most web apps because page scripts cannot read it, which limits the damage of a cross-site scripting bug. localStorage is simpler but exposes the token to any script running on the page.
Is an OAuth access token always a JWT?
No. Some providers issue JWT access tokens and others issue opaque strings that only the authorisation server can interpret. OpenID Connect ID tokens, by contrast, are always JWTs.
How long should a JWT be valid?
Keep access tokens short-lived, typically minutes rather than days, because a JWT cannot easily be revoked before it expires. Use refresh tokens or a new sign-in to issue fresh ones.