JWT decoder, debugger and generator

Paste a JSON Web Token to debug it: read its header and payload, see whether it has expired, and check an HS256 signature if you have the secret. Everything happens in this page: the token is never sent anywhere, and you can watch the Network tab to confirm it.

Header

Payload

—

What the claims mean

—Paste a token above.

Check the signature (HS256 only)

If the token uses HS256 and you have the shared secret, this checks it here in the browser. RS256 and ES256 need the issuer's public key and are not checked here.

Generate a test JWT (HS256)

Write a payload, pick a secret, and get a signed token to test your API with. Signed here with your browser's Web Crypto; nothing is sent. Use a test secret only: anyone who knows it can mint tokens your server will accept.

Things worth knowing

Testing an API that needs a token?

HeaderForge sets the Authorization header for the sites you choose, keeps the value in a variable like {{token}} so it stays out of your exported rules, warns you when a rule carries a credential, and shows whether the rule actually fired. Free, no analytics, no account.

Get HeaderForge for Chrome