JWT Decoder
Decode a JSON Web Token's header and payload and read its security warnings. Supply a key and the tool verifies the signature too.
This is generated in browser and is not sent to pah.moi servers.
About this tool3 paragraphs
Verification covers HS*, RS*, PS*, ES* and EdDSA, against a secret, a PEM public key, or a JWK or JWKS key file you supply. The claims it checks are exp (expiry), nbf (not before), iat (issued at), the issuer and the audience, with a small documented allowance for clocks that disagree. Expert mode builds demo tokens and drops them back into the inspector.
A verified signature proves who signed a token, not that the token should be trusted: the banner says VERIFIED, never safe.
A JWT is a bearer credential: anyone holding it can use it. So the tool is gated behind a short acknowledgement. Your token, secret and keys never leave the browser and nothing here is logged.
jwt-cli from the site's source with:
cargo build --release --bin jwt-cliSource and licence terms