JWT Validator

Verify JWT signature, expiration, and claims.

What is JWT validation?

JWT validation has three parts: (1) verify the signature to prove the token wasn't tampered with, (2) check exp to ensure it hasn't expired, (3) check nbf to ensure it's valid yet. All three must pass for the token to be accepted.

Decode vs Verify vs Validate

Privacy

Your token and secret never leave your device.

Frequently Asked Questions

What does this tool do?

Validates a JWT: checks the signature (HMAC-SHA), expiration (exp), and not-before (nbf) claims.

What algorithms are supported?

HS256, HS384, HS512. RS256 (RSA) is not supported because it requires the public key.

Do I need the secret key?

Only to verify the signature. You can leave it blank to just check expiration and view the payload.

What is nbf?

Not Before — the time before which the token must not be accepted. If nbf is in the future, the token isn't valid yet.

Is my secret uploaded?

No. Everything runs in your browser.

Related Tools