JWT Decoder & Debugger

Paste a JWT to inspect header and payload, check expiry claims, and verify signatures locally in your browser.

Private by design

RookJWT processes tokens entirely client-side. No JWT is uploaded to RookVPN servers. Your secret keys and tokens never leave your browser tab.

Decode and verify

Read standard claims (exp, iss, aud, sub) and optionally verify HS256/RS256 signatures with jose + Web Crypto. Works with any JWT from any identity provider.

How this page is different

JWT Decoder & Debugger exists to decode a JSON Web Token in the browser, and verify a signature only when you also have the key. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.

Do this on the page

Work through JWT Decoder & Debugger in order. 1. Paste the token. 2. Read header and payload, including exp. 3. Verify only if you have the right secret or public key. 4. Do not paste production refresh tokens into a screen share. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.

What this page will not decide for you

Decode is not verify. A decoded payload can be forged. The signature check stays in the browser. This is not an authorization server. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.

A concrete example

Example: the payload says exp is yesterday. The token is expired even if the signature would have been valid. You do not disable verification in your API to make the call work. You issue a new token. If you only decoded and never checked the signature, you have not learned whether the issuer signed those claims.

Where to go next

After you finish JWT Decoder & Debugger, open the decode page or the verify page for the one step you are on if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.

If you only remember one thing

Use JWT Decoder & Debugger for one job: to decode a JSON Web Token in the browser, and verify a signature only when you also have the key. Bring the before-and-after evidence with you if you change a setting. A VPN icon, a decoded token, a generated password, or a stripped file is not finished until you have checked the output the way this page describes. Then follow the related guide for the long version, and the sibling tool only when the next job is actually different. Keep secrets out of the same message as the link or the file that needs them. If a second run does not match the first, stop and find what changed instead of publishing the first result.

Field notes

Example: the payload says exp is yesterday. The token is expired even if the signature would have been valid. You do not disable verification in your API to make the call work. You issue a new token. If you only decoded and never checked the signature, you have not learned whether the issuer signed those claims. Work the page in this order: Paste the token. Read header and payload, including exp. Verify only if you have the right secret or public key. Do not paste production refresh tokens into a screen share. Limits that still apply after a clean result: Decode is not verify. A decoded payload can be forged. The signature check stays in the browser. This is not an authorization server.

Frequently asked questions

Is it safe to decode JWT tokens online?

Only if decoding is client-side. RookJWT never sends tokens to a server — all processing is done in your browser using JavaScript.

Does decoding verify the signature?

Decoding shows header/payload without validation. Use the verify flow with your secret or public key to validate the signature cryptographically.

What JWT algorithms does RookJWT support?

RookJWT supports HS256, HS384, HS512 (HMAC) and RS256, RS384, RS512 (RSA) via the jose library and Web Crypto API.

Is the token sent to RookVPN?

No. Decode and verify run locally.

Does a successful decode mean it is authentic?

No. Verify with the key.

What is exp?

The expiry time, in seconds since the Unix epoch.

JWT decoder guide Hash generator Password generator