What this does
Decodes a JSON Web Token (JWT) into its header, payload, and signature, shows you when it was issued and when it expires, and checks an HMAC signature against a secret you provide. The Generate tab builds and signs a new token from a header and payload you write.
How it works
A JWT is three base64url-encoded parts joined by dots: header.payload.signature. Decoding just reverses that encoding, so it works even on a malformed or unverifiable token. Verifying the signature is a separate step: it only supports the HMAC algorithms HS256, HS384, and HS512, since those are the ones that can be checked with a plain secret instead of a public/private key pair.
Privacy
This runs entirely in your browser. Nothing is uploaded. The token, secret, and decoded payload are kept only in memory for this tab and are never logged or saved.