Developer tool

JWT Decoder and Verifier

Decode JWT claims and optionally verify a supported signature using browser cryptography.

Free browser tool

No Matrix computer needed

✓ No account or card

✓ Use the result right away

✓ Task-specific limits below

Workspace

Use jwt decoder and verifier

A decoded token is untrusted until its signature is verified. Treat real access tokens as credentials.

Verification happens in this browser. HMAC secrets and SPKI PEM RSA public keys are supported. Never paste a private key.

Token details

Decode the JWT to inspect its header and claims. Nothing is sent to Matrix.

How to use it

Paste a compact JWT to inspect its header and claims, then supply a secret or RSA public key to verify it.

What to check

Decoded claims are untrusted until verification. Supports HS256/384/512 and RS256/384/512, not every JWT algorithm or issuer policy.

Review the result before using it in a published page, application, or agent configuration.

Quick answers

Frequently asked questions

Are decoded JWT claims trusted immediately?

No. Anyone can construct a token-shaped string. Treat claims as unverified until a supported signature is checked against a trusted key.

Which JWT signatures can Matrix verify?

The browser supports HS256, HS384, HS512, RS256, RS384, and RS512. Verification does not replace issuer, audience, or application policy checks.

Keep exploring

Related free tools

Need this work to keep going?

Matrix gives agents a private cloud computer for files, connected tools, and work that continues after you close your laptop. The browser tool above is free; a Matrix computer requires a paid plan.

Explore Matrix