English
← Back to Top

JWT Debugger

JWT Debugger & Decoder

Securely decode, verify, and edit JWTs locally in your browser.

How to Use

1

Paste the JWT (JSON Web Token) you want to inspect into the 'Encoded JWT' input area. (You can also preload a token using the ?token=... URL parameter.)

2

The token's Header and Payload will be instantly decoded and beautifully formatted as JSON.

3

You can directly edit the decoded JSON (Header or Payload). The tool will re-encode your changes into a new JWT string in real-time, making it perfect for API testing.

4

To verify the token's Signature, enter your Secret Key (for HMAC) or Public Key (for RSA) in the verification field. The validation result will be displayed immediately.

Why Choose Madao Factory?

100% Secure & Client-Side Processing:

Every step, from decoding to signature verification, is executed entirely within your browser. Your sensitive JWTs and cryptographic keys are never sent to external servers, guaranteeing maximum privacy for enterprise use.

Accurate Multi-Byte Decoding:

Our advanced Base64Url normalization ensures that multi-byte characters (like Japanese or Chinese) embedded in the Payload are accurately decoded and rendered without any garbling.

Real-Time Two-Way Editing:

Go beyond simple decoding. Edit the JSON payload on the fly and watch the tool instantly generate a new, encoded JWT string. Ideal for spoofing parameters during API penetration testing.

Smart Timestamp Parsing & Expiration Checks:

Automatically detects UNIX timestamps (exp, iat, nbf) and converts them into readable local times. It visually highlights whether the token is currently 'Active' or 'Expired'.

Offline Signature Verification via Web Crypto API:

Leverage native browser cryptography to securely and instantly verify token signatures against tampering, supporting both HMAC (HS256/384/512) and RSA (RS256/384/512) algorithms.

Frequently Asked Questions

Is it safe to paste confidential production tokens?

Absolutely. The tool operates 100% locally. No data, tokens, or keys are ever transmitted over the network to our servers.

Which cryptographic algorithms do you support for verification?

We currently support comprehensive validation for HMAC algorithms (HS256, HS384, HS512) and RSA algorithms (RS256, RS384, RS512).

What happens if my token uses alg='none'?

The tool will successfully decode the payload, but it will immediately flag a critical security warning regarding the 'none' algorithm and skip the signature verification process.