JWT Debugger

Decode, verify and re-sign JSON Web Tokens locally.

Works offline Native desktop macOS & Windows
JWT Debugger
What it does

A bearer token pasted into an online decoder is a token you have handed to a third party. The JWT Debugger in HackUtilities decodes header and payload, checks the signature against a secret or public key, and lets you edit and re-sign HMAC tokens, all on your machine. Use it to debug expired sessions and claim mismatches without exposing live credentials.

Decode header and payload

The token is split into colored header, payload and signature parts. Claims are listed in a table with their values as JSON.

Time claim status

exp, iat, nbf and auth_time are converted to your local date and time. exp shows an expired or valid badge, and a future nbf shows not yet valid.

Signature verification

Verify HS256, HS384 and HS512 tokens with a secret, or RS, ES and PS tokens (256, 384, 512) with an SPKI PEM public key. Expiry is ignored during verification so you can debug expired tokens.

Edit and re-sign

Change the payload JSON and re-sign an HMAC token with your secret to produce a new token with the same header.

Security warnings

Tokens with alg none are flagged as unsigned, and HS256 secrets shorter than 32 bytes are marked weak.

FAQ

Is it safe to paste a production JWT?

The decoding and verification run inside the app on your machine, and the tool makes no network requests. The token is not sent anywhere.

Can I verify tokens signed with a JWKS or a certificate?

Not directly. Public key verification expects a single public key in SPKI PEM format (BEGIN PUBLIC KEY). Other algorithms, including EdDSA, are decoded but cannot be verified.

Pairs well with
All 46 tools →
Try JWT Debugger free for 14 days

No card, no account. Every tool included, bought once.

Download