◇ Security & Cryptography

JWT Decoder

Decode JWT header and payload locally so you can inspect claims and expiry quickly.

Updated

HMAC verification Claims inspector ASP.NET Core claim mapping Security warnings

Loading JWT Decoder…

What this page sends

  • Your input: Processed in this tab and not sent to a server.
  • Share links: Share links put a Base64 copy of your input and output in the URL itself (after #d=). Anyone with the link can read it, so don't share a link that contains secrets.
  • Page load: Loading the page requests HTML, scripts and images from ByteKiln, fonts from Google Fonts, and sends Google Analytics page views, tool-usage events and catalog interactions (tool/category IDs, result status and whether a click followed search — never your input, output or search terms). Privacy & sharing

How the JWT Decoder Works

The ByteKiln JWT Decoder splits your token into its three Base64URL-encoded segments and decodes each locally in your browser. For HMAC tokens, it also verifies the signature using the Web Crypto API, without a network request.

Decoding header and payload

A JWT token is three Base64URL segments separated by dots. The decoder splits, decodes, and pretty-prints each segment as JSON. Decoding uses JavaScript in the page; the token is not sent to a server.

Signature verification

For HS256, HS384, and HS512 tokens, enter your HMAC secret in the Signature panel. The tool re-computes the expected signature using SubtleCrypto.sign() and compares it byte-for-byte against the token's embedded signature.

ASP.NET Core claim mapping

The "As ASP.NET Core sees them" view applies the 74-entry DefaultInboundClaimTypeMap from Microsoft.IdentityModel: sub becomes ClaimTypes.NameIdentifier, role and roles become the long role URI, and unique_name (not name) becomes ClaimTypes.Name. Array claims are split into one claim per value. It then says what [Authorize(Roles)] and User.Identity.Name will read, in mapped mode or with MapInboundClaims = false.

Claims and security warnings

The claims inspector shows human-readable dates for exp, iat, and nbf. Security warnings appear when the algorithm is "none", when exp is missing from the payload, or when the token has already expired.

Limitations

  • Decoding is not verification. Unless you enter the HMAC secret or a public JWK, the header and claims are simply what the token says about itself.
  • Keys are not fetched: for RS/ES tokens you paste the JWK or JWKS yourself — the tool doesn't download a provider's jwks_uri.
  • It checks exp, nbf and the signature only. Audience, issuer, scopes and revocation are your API's job, and encrypted tokens (JWE, five segments) can't be decoded.
  • Share links contain the token in readable form. Never share a link for a token that is still valid.
  • The ASP.NET Core view applies the default inbound claim map only; custom maps, claims transformations and Identity Web defaults are not modelled.

FAQ

Short answers for the things developers usually ask before trusting a tool.

Why does [Authorize(Roles = "admin")] fail when my JWT has "role": "admin"?

Usually because of claim mapping. By default ASP.NET Core rewrites "role" to http://schemas.microsoft.com/ws/2008/06/identity/claims/role, and RoleClaimType expects that long URI. If you set MapInboundClaims = false, the claim stays "role" and the check fails until you set TokenValidationParameters.RoleClaimType = "role". Roles inside "groups" or Keycloak's realm_access are never read. Switch the Claims panel to "As ASP.NET Core sees them" to check.

Can the ByteKiln JWT Decoder verify JWT signatures?

Yes — for HS256, HS384, and HS512 tokens. Enter your HMAC secret in the Signature panel and the tool verifies the signature locally using the browser's SubtleCrypto API. RS256 and asymmetric algorithms are not yet supported.

Does it tell me if the JWT token is expired?

Yes. If the payload includes an exp claim, the tool compares it against the current time and shows a clear Valid or Expired status badge. The exact expiry date and time are also displayed.

What security warnings does the JWT Decoder show?

The tool warns when the algorithm is set to "none" (no cryptographic signature), when the exp claim is missing entirely, or when the token has already expired. These are common JWT security issues to watch for.

Is my JWT token sent to a server?

No. The token is decoded in your browser and is not sent to a ByteKiln server or logged by the tool. If you press Share, the link contains the token in readable form, so never share a link for a live token.

What is the difference between the JWT header and payload?

The header identifies the token type and signing algorithm (e.g. HS256). The payload contains the claims — statements about the subject like user ID, roles, and expiry time. Both sections are Base64URL-encoded JSON objects.

Related tools

Useful follow-ups when one conversion usually turns into three more.

Want the background and worked examples? There's a longer write-up.

Read the JWT Decoder guide

Related guides