JWT Inspector — decode any token in your browser

Zero upload · nothing leaves this tab

JWT Inspector

Paste a JSON Web Token to see its decoded header, every claim and an instant expiry verdict — decoded in your browser, never sent to a server.

No network requests Unicode-safe (UTF-8) HS256 / HS384 / HS512 verify

Decode a token

Segments
header.payload.signature
Optional: check the signature and the algorithm

A secret typed here is fed only into your browser's WebCrypto HMAC — it is never uploaded, stored or logged.

Flags an alg mismatch with the token header.
Only meaningful for HS* tokens. The sample token is signed with hunter2.

Decoding happens locally in this tab. No token, claim or secret is uploaded, logged or sent anywhere.

Waiting for a token

Paste a JWT on the left — the verdict appears here.

Header
Paste a token to see the decoded header.
Signature check runs after you paste a token.

How it works

The whole inspection runs locally in three steps — no request ever leaves the tab.

1 · Paste

Drop the token straight out of a log or DevTools. A Bearer prefix and stray line breaks are stripped for you.

2 · Decode

The three base64url segments are decoded as UTF-8 and printed as JSON, alongside a flat claim table with real dates.

3 · Judge

An expiry badge humanises exp and nbf, while the algorithm and signature checks flag anything suspect.

What it checks

Expiry verdict

Valid with a humanised countdown, Expired with how long ago, Not yet valid, or No expiry claim — a string exp is coerced with a warning instead of being reported as expired.

HMAC signature

HS256, HS384 and HS512 are recomputed with WebCrypto against a secret you type. A wrong secret reports a mismatch — never a green tick.

Algorithm hygiene

An expected-algorithm selector surfaces alg mismatches, and alg: none is called out as unsigned instead of silently passing.

Broken input

Two-segment strings and opaque API keys get an inline error with the segment count. Non-JSON payloads fall back to raw decoded text.

Unicode claims

Segments are decoded as UTF-8 bytes, so non-ASCII names, issuer strings and emoji survive intact.

Zero upload

No fetch, no XHR, no analytics. Paste a production token and watch DevTools stay silent.

FAQ

Is my token sent anywhere?

No. Decoding, expiry maths and the HMAC signature check all run in this tab with atob, TextDecoder, JSON.parse and WebCrypto. There is not a single network request on this page.

Can it verify RS256, ES256 or PS256 tokens?

Not the signature — those need the issuer's public key, which a zero-upload tool never has. The header and payload still decode exactly, and the verdict says so explicitly rather than pretending the token is valid.

Why does my token show "Not a JWT"?

A compact JWS has exactly two dots and three non-empty base64url segments. Session cookies, opaque access tokens and API keys do not, and this tool refuses to guess at a partial decode.

An expiry looks wrong — who do I trust?

Numeric date claims are seconds since the Unix epoch. The claim table prints each one as an ISO timestamp next to a humanised delta, so you can see at a glance which side of the comparison is skewed.

Latest updates

More free tools

Step-by-step guides in our blog & guides.

Hijri Gregorian Date Converter Free Unit Converter Tags Generator Free For Youtube التحويل من Mp4 الى Mp3 محول Pdf الى وورد Password Generator With Words Free Online Square Foot Calculator Resume Builder Top Rated Free Online Meme Maker Cron Expression Generator