-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathjwt.html
More file actions
265 lines (241 loc) · 13.9 KB
/
Copy pathjwt.html
File metadata and controls
265 lines (241 loc) · 13.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>JWT Decoder — read claims and verify HS256, entirely offline | JSON Studio</title>
<meta name="description" content="Decode a JSON Web Token in your browser: header, claims, expiry and validity, with optional HS256/384/512 signature verification. Your token is never transmitted — which matters, because a JWT is a live credential.">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://jsonstudio.msdevbuild.com/jwt.html">
<link rel="manifest" href="manifest.webmanifest">
<meta name="theme-color" content="#0078d4" media="(prefers-color-scheme: light)">
<meta name="theme-color" content="#12151c" media="(prefers-color-scheme: dark)">
<link rel="apple-touch-icon" href="assets/img/apple-touch-icon.png">
<meta name="apple-mobile-web-app-capable" content="yes">
<meta name="apple-mobile-web-app-title" content="JSON Studio">
<link rel="icon" href="assets/img/favicon.svg" type="image/svg+xml">
<meta property="og:type" content="website">
<meta property="og:title" content="JWT Decoder — read claims and verify HS256, entirely offline">
<meta property="og:description" content="Decode a JSON Web Token in your browser: header, claims, expiry and validity, with optional HS256/384/512 signature verification. Your token is never transmitted — which matters, because a JWT is a live credential.">
<meta property="og:url" content="https://jsonstudio.msdevbuild.com/jwt.html">
<meta property="og:image" content="https://jsonstudio.msdevbuild.com/assets/img/og-cover.png">
<meta property="og:image:width" content="1200">
<meta property="og:image:height" content="630">
<meta property="og:image:alt" content="JSON Studio — every JSON tool, in your browser">
<meta property="og:site_name" content="JSON Studio by MSDEVBUILD">
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:image" content="https://jsonstudio.msdevbuild.com/assets/img/og-cover.png">
<meta name="twitter:title" content="JWT Decoder — read claims and verify HS256, entirely offline">
<meta name="twitter:description" content="Decode a JSON Web Token in your browser: header, claims, expiry and validity, with optional HS256/384/512 signature verification. Your token is never transmitted — which matters, because a JWT is a live credential.">
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500;700&display=swap" rel="stylesheet">
<link rel="stylesheet" href="assets/css/styles.css">
<link rel="stylesheet" href="assets/css/convert.css">
<link rel="stylesheet" href="assets/css/present.css">
<link rel="stylesheet" href="assets/css/workbench.css">
<link rel="stylesheet" href="assets/css/tool-focus.css">
<link rel="stylesheet" href="assets/css/editor.css">
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "SoftwareApplication",
"name": "JWT decoder & verifier — JSON Studio",
"url": "https://jsonstudio.msdevbuild.com/jwt.html",
"applicationCategory": "DeveloperApplication",
"operatingSystem": "Any (runs in browser)",
"offers": { "@type": "Offer", "price": "0", "priceCurrency": "USD" },
"creator": { "@type": "Person", "name": "Suthahar Jegatheesan", "url": "https://www.msdevbuild.com/" },
"description": "Decode a JSON Web Token and read its header, claims and expiry. Optional HMAC signature verification, entirely in your browser — your token is never sent anywhere."
}
</script>
<script>(function(){try{var t=localStorage.getItem('json-studio-theme');if(!t&&window.matchMedia&&matchMedia('(prefers-color-scheme: dark)').matches)t='dark';if(t)document.documentElement.setAttribute('data-theme',t);}catch(e){}})();</script>
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "BreadcrumbList",
"itemListElement": [
{ "@type": "ListItem", "position": 1, "name": "JSON Studio", "item": "https://jsonstudio.msdevbuild.com/" },
{ "@type": "ListItem", "position": 2, "name": "Tools", "item": "https://jsonstudio.msdevbuild.com/tools.html" },
{ "@type": "ListItem", "position": 3, "name": "JWT decoder", "item": "https://jsonstudio.msdevbuild.com/jwt.html" }
]
},
{
"@type": "FAQPage",
"mainEntity": [
{ "@type": "Question", "name": "Is my token sent anywhere?", "acceptedAnswer": { "@type": "Answer", "text": "No, and this is the one page where that matters most. Decoding and verification both happen in your browser. There is no backend to receive it." } },
{ "@type": "Question", "name": "Can it verify RS256 or ES256 tokens?", "acceptedAnswer": { "@type": "Answer", "text": "No. Those are signed with a private key and verified with the matching public key, which this tool does not ask for. RS/ES tokens are decoded and clearly reported as unverified." } },
{ "@type": "Question", "name": "Does decoding mean the token is valid?", "acceptedAnswer": { "@type": "Answer", "text": "No. Anyone can read a JWT — the payload is only base64-encoded, not encrypted. Only a signature check with the right key proves it is genuine, which is what the secret field is for." } }
]
},
{
"@type": "HowTo",
"name": "How to use the JWT decoder",
"step": [
{ "@type": "HowToStep", "position": 1, "text": "Paste the token (a \"Bearer \" prefix is fine — it gets stripped)." },
{ "@type": "HowToStep", "position": 2, "text": "Read the header and claims; timestamps are annotated with how long ago or how far ahead they are." },
{ "@type": "HowToStep", "position": 3, "text": "Optionally paste the signing secret to verify an HS256, HS384 or HS512 signature." }
]
}
]
}
</script>
</head>
<body>
<div id="site-header"></div>
<span id="top"></span>
<main class="convert-shell">
<div class="convert-head">
<div class="container tool-topbar">
<h1>JWT decoder</h1>
<p class="tt-sub">Read a token’s header, claims and expiry — and verify HS256 locally.</p>
<a class="tt-about" href="#about">About & FAQ ↓</a>
</div>
<div class="container">
<div class="opt-bar">
<div class="opt" style="flex:1;min-width:260px;">
<label for="opt-secret">HMAC secret</label>
<input type="text" id="opt-secret" placeholder="optional — verifies HS256/384/512" style="flex:1;font-family:'JetBrains Mono',monospace;">
</div>
<div class="opt">
<input type="checkbox" id="opt-b64">
<label for="opt-b64" style="cursor:pointer;">Secret is base64</label>
</div>
</div>
</div>
</div>
<div class="convert-grid three">
<section class="pane">
<div class="pane-head">
<div class="pane-title">Encoded token</div>
<button id="btn-sample">Load sample</button>
<button id="btn-clear">Clear</button>
</div>
<div class="pane-body">
<textarea id="input" class="code-area" spellcheck="false" placeholder="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.…"></textarea>
</div>
<div class="pane-status" id="in-status">Waiting for input.</div>
</section>
<section class="pane">
<div class="pane-head">
<div class="pane-title">Header</div>
<button class="primary" id="btn-run">Decode</button>
</div>
<div class="pane-body">
<textarea id="output-header" class="code-area" spellcheck="false" readonly placeholder="Header appears here."></textarea>
</div>
<div class="pane-status" id="header-status"></div>
</section>
<section class="pane">
<div class="pane-head">
<div class="pane-title">Payload / claims</div>
<button id="btn-copy">Copy</button>
<button id="btn-download">Download</button>
</div>
<div class="pane-body">
<textarea id="output" class="code-area" spellcheck="false" readonly placeholder="Claims appear here."></textarea>
<p class="note">Decoding is not verification. Without a secret this only reads the token; with one, HS256/384/512 signatures are checked via WebCrypto in the browser. RS/ES tokens need a public key and are not verified here.</p>
</div>
<div class="pane-status" id="out-status"></div>
</section>
</div>
</main>
<section class="tool-home" id="about">
<div class="container">
<div class="th-more">Reference</div>
<header class="th-head">
<div class="kicker">JWT decoder</div>
<h2>About the JWT decoder</h2>
<p>A JWT is a credential. Pasting one into a website that decodes it server-side hands someone a session, which is why this decoder runs entirely in the page: the token is split and base64url-decoded locally, and if you supply the signing secret, the HMAC signature is verified with the browser's own WebCrypto. Expiry and not-before claims are worked out for you in plain language.</p>
<div class="cta-row">
<a class="btn-primary" href="#top">Use the tool ↑</a>
<a class="btn-secondary btn-present" href="presentation.html"><svg class="nav-ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><rect x="3" y="4" width="18" height="13" rx="2"/><path d="M12 17v3M9.5 20h5"/><path d="m10.6 8.8 4 2.7-4 2.7z" fill="currentColor" stroke="none"/></svg> Present it</a>
</div>
</header>
<div class="th-features">
<div class="th-feature">
<div class="fi">01</div>
<h3>Header and claims</h3>
<p>Both halves decoded and pretty-printed, with UTF-8 claims intact.</p>
</div>
<div class="th-feature">
<div class="fi">02</div>
<h3>Expiry in plain language</h3>
<p>exp, iat and nbf are shown as real dates plus "in 42 minutes" or "3 days ago".</p>
</div>
<div class="th-feature">
<div class="fi">03</div>
<h3>Real HS256 verification</h3>
<p>Supply the secret and the signature is checked with WebCrypto, in the page.</p>
</div>
<div class="th-feature">
<div class="fi">04</div>
<h3>Never transmitted</h3>
<p>A JWT is a live credential. This one is decoded locally and goes nowhere near a server.</p>
</div>
</div>
<div class="seo-grid">
<div class="seo-main">
<h3 id="how">How to use it</h3>
<ol class="seo-steps">
<li>Paste the token (a "Bearer " prefix is fine — it gets stripped).</li>
<li>Read the header and claims; timestamps are annotated with how long ago or how far ahead they are.</li>
<li>Optionally paste the signing secret to verify an HS256, HS384 or HS512 signature.</li>
</ol>
<h3 id="faq">Questions</h3>
<div class="faq">
<details>
<summary>Is my token sent anywhere?</summary>
<div class="faq-body"><p>No, and this is the one page where that matters most. Decoding and verification both happen in your browser. There is no backend to receive it.</p></div>
</details>
<details>
<summary>Can it verify RS256 or ES256 tokens?</summary>
<div class="faq-body"><p>No. Those are signed with a private key and verified with the matching public key, which this tool does not ask for. RS/ES tokens are decoded and clearly reported as unverified.</p></div>
</details>
<details>
<summary>Does decoding mean the token is valid?</summary>
<div class="faq-body"><p>No. Anyone can read a JWT — the payload is only base64-encoded, not encrypted. Only a signature check with the right key proves it is genuine, which is what the secret field is for.</p></div>
</details>
</div>
</div>
<aside class="seo-side">
<div class="seo-card" id="share">
<h3>Share this tool</h3>
<p>Send it to a colleague — the link only, never anything you have pasted in.</p>
<div data-share data-share-title="JWT decoder — JSON Studio"></div>
</div>
<div class="seo-card">
<h3 class="with-ico"><svg class="nav-ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><rect x="3" y="4" width="18" height="13" rx="2"/><path d="M12 17v3M9.5 20h5"/><path d="m10.6 8.8 4 2.7-4 2.7z" fill="currentColor" stroke="none"/></svg> Present this tool</h3>
<p>Demoing to a client or a class? Press <kbd>Shift</kbd><kbd>P</kbd> for full-screen presentation mode — chrome hidden, type scaled up, laser pointer included.</p>
<a class="seo-link" href="presentation.html">How presentation mode works →</a>
</div>
<div class="seo-card">
<h3>Related tools</h3>
<ul class="seo-related">
<li><a href="format.html"><span class="ri">⌗</span>Formatter & validator</a></li>
<li><a href="tool.html"><span class="ri">{ }</span>JSON to diagram</a></li>
<li><a href="validate.html"><span class="ri">✓</span>Schema validator</a></li>
</ul>
<a class="seo-link" href="tools.html">All 14 tools →</a>
</div>
<div class="seo-card quiet">
<h3>Private by construction</h3>
<p>No backend exists. Everything on this page runs in your browser, so nothing you paste is uploaded, logged or retained.</p>
<a class="seo-link" href="privacy.html">Read the privacy policy →</a>
</div>
</aside>
</div>
</div>
</section>
<div id="site-footer"></div>
<script src="assets/js/site.js"></script>
<script src="assets/js/payload-link.js"></script>
<script src="assets/js/tool-kit.js"></script>
<script src="assets/js/jwt.js"></script>
<script src="assets/js/present.js"></script>
<script src="assets/js/workbench.js"></script>
<script src="assets/js/history.js"></script>
<script src="assets/js/gutter.js"></script>
<script src="assets/js/editor.js"></script>
<script src="assets/js/share.js"></script>
</body>
</html>