readme.now

JWT Debugger | Decode, Edit, and Verify JWTs Locally

Secure, client-side JWT debugger. Decode JSON Web Tokens, edit the payload, and verify signatures locally without your secret keys ever leaving your browser.

JWT Debugger
Signatures are generated entirely locally using Web Crypto API. Tokens never leave browser.
Encoded Token
Header: Algorithm & Token Type
Payload: Data
Verify Signature

Advanced JWT Manipulation
& Testing Suite

Essential for bug bounty hunters and penetration testers. Modify JWT payloads and test for signature vulnerabilities directly in your browser. Supports "none" algorithm testing and secure signature verification locally.

100% Local•Zero Latency•Open Logic

JWT decoding is not signature verification

A JWT header and payload are Base64url-encoded, not encrypted. Anyone holding a token can decode those claims. Trust the claims only after verifying the signature, expected algorithm, issuer, audience, and time constraints.

Example input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJleHAiOjAwMDAwMDAwMDB9.signature

Expected output

{ "sub": "123", "exp": 0 }

Behavior

  • Separates and decodes the header, payload, and signature segments.
  • Displays common registered claims such as exp, nbf, iss, aud, and sub.
  • Verification requires the correct key and an explicitly trusted algorithm.

Limits and edge cases

  • Successful decoding says nothing about authenticity.
  • Never paste production secrets into an unfamiliar device or shared browser.
  • An expired token may still decode cleanly but must not be accepted.

Processing note: tool input stays in the browser. Readme.now analytics records page usage, not the payload you paste or the generated output.

Authoritative reference: RFC 7519: JSON Web Token

Continue the workflow without copying data to a server.