Related tools
- Password Strength CheckerScore a password's real entropy and crack time, with plain English reasons, on your device.
- HMAC GeneratorCompute and verify HMAC digests for a message and a secret key, in your browser.
- JWT GeneratorBuild, sign, and verify JSON Web Tokens with HS256, RS256, or ES256 locally.
- Certificate DecoderDecode PEM or DER X.509 certificates to read expiry, SANs, issuer, fingerprints, and chain order.
- Bcrypt & Argon2 HasherHash and verify passwords with bcrypt, argon2, and scrypt, entirely in your browser.
- Hash IdentifierWork out which algorithm likely produced an unknown hash, ranked by likelihood.
What it does
Decodes any JSON Web Token into its header and payload, spells out the registered claims (issuer, subject, audience, expiry) with human readable dates, and tests the token for two classic weaknesses: the alg=none trick that leaves a token unsigned, and HMAC secrets that are weak or guessable. Give it a secret or a wordlist and it recomputes the HS256, HS384, or HS512 signature to tell you whether the token verifies. Every check runs on tokens you are authorized to test.
How to use it
Paste a token in the header.payload.signature form. The decoded claims and any alg=none finding appear immediately. To test an HMAC secret, type it into the signing secret field, or paste a list of candidate secrets one per line; the tool also tries a built in list of common secrets and reports a match as a critical finding. Set a time override to check expiry against a fixed moment instead of the live clock.
Why this one
The usual move is to paste a token into jwt.io or an online cracker, but a real token is a live credential and those sites receive it on their servers. Here the token never leaves your device, so there is nothing to log, retain, or leak. No sign in, no rate limits, and it keeps working offline.
FAQ
- Is it safe to paste a real token?
- The token stays in your browser and is never sent anywhere, so pasting one here is far safer than pasting it into an online decoder. Even so, treat anything you have pasted into any tool as potentially exposed and rotate or revoke it afterward as good hygiene.
- What is alg=none?
- alg=none is a JWT header that declares the token has no signature. A server that honors it will accept a token with any payload, so an attacker can forge an admin token by editing the claims. If this tool flags alg=none, make sure your backend rejects unsigned tokens.
- Can it crack strong secrets?
- No. It only catches weak, common, or guessable HMAC secrets by testing a small built in list plus any wordlist you provide. A long random secret will not be found, which is exactly why you should use one.
Keyboard shortcuts: press ? anywhere on this page to see them.