JWT Debugger
Decode, verify and re-sign JSON Web Tokens locally.
A bearer token pasted into an online decoder is a token you have handed to a third party. The JWT Debugger in HackUtilities decodes header and payload, checks the signature against a secret or public key, and lets you edit and re-sign HMAC tokens, all on your machine. Use it to debug expired sessions and claim mismatches without exposing live credentials.
Decode header and payload
The token is split into colored header, payload and signature parts. Claims are listed in a table with their values as JSON.
Time claim status
exp, iat, nbf and auth_time are converted to your local date and time. exp shows an expired or valid badge, and a future nbf shows not yet valid.
Signature verification
Verify HS256, HS384 and HS512 tokens with a secret, or RS, ES and PS tokens (256, 384, 512) with an SPKI PEM public key. Expiry is ignored during verification so you can debug expired tokens.
Edit and re-sign
Change the payload JSON and re-sign an HMAC token with your secret to produce a new token with the same header.
Security warnings
Tokens with alg none are flagged as unsigned, and HS256 secrets shorter than 32 bytes are marked weak.
Is it safe to paste a production JWT?
The decoding and verification run inside the app on your machine, and the tool makes no network requests. The token is not sent anywhere.
Can I verify tokens signed with a JWKS or a certificate?
Not directly. Public key verification expects a single public key in SPKI PEM format (BEGIN PUBLIC KEY). Other algorithms, including EdDSA, are decoded but cannot be verified.
Encode and decode Base64 for text, files, URL-safe strings and images.
Open →MD5, SHA, BLAKE3 and CRC32 hashes and HMAC for text and files.
Open →Convert Unix timestamps to readable dates and back.
Open →No card, no account. Every tool included, bought once.