JWT Decoding vs Encoding

Understand the difference between decoding a JWT (reading it) and encoding or signing one (creating it), and which tool to use for each.

Decoding and encoding a JWT are opposite operations, and confusing them is easy because both deal with the same three-part token format.

JWT Decoder

  • Reads the header and payload of an existing token by Base64URL-decoding them.
  • Requires no secret or key, because the first two parts are only encoded, not encrypted.
  • Does not verify the signature, so it cannot confirm the token was not tampered with.
Open JWT Decoder

JWT Encoder

  • Creates and signs a new token with an HMAC algorithm such as HS256, HS384 or HS512.
  • Requires a secret key, which is used to compute the signature and stays in the browser.
  • Produces a token you can then decode or hand to a server for later verification.
Open JWT Encoder

Verdict

Use the decoder to inspect a token you received, and the encoder to mint a token for testing or for a client that expects an HMAC-signed JWT.