JWT Decoder & Inspector
SecurityDecode and inspect JSON Web Tokens (Header, Payload, Claims, Expiration) with client-side verification.
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "1234567890",
"name": "Alex Developer",
"admin": true,
"iat": 1516239022,
"exp": 1899849900
}Local Signature Verification
Verify HMAC HS256 signatures client-side using Web Crypto API. Secret never leaves your machine.
About JWT Decoder & Inspector
A JSON Web Token (JWT) is a compact, URL-safe means of representing claims between two parties. A token consists of three Base64URL-encoded parts separated by dots: the Header (algorithm and token type), the Payload (user claims and expiration timestamp), and the cryptographic Signature.
Zero-Upload Privacy Guarantee
Never paste production Bearer tokens or admin session JWTs into unknown third-party websites. Other online tools might log tokens and compromise user accounts. DevTools runs purely in your browser memory.
Key Capabilities & Features
How to use this JWT decoder
Paste JWT Token
Paste any Bearer or ID token into the input field. Colors separate Header, Payload, and Signature.
Inspect Claims & Timestamps
Review standard claims like 'exp' (expiration), 'iat' (issued at), 'iss' (issuer), and 'sub' (subject).
Check Expiration Status
Notice the live badge displaying whether the token is currently valid or expired, with relative countdown.
Test Signature Locally (Optional)
Enter your HMAC secret (for HS256/384/512) to verify signature validity directly using Web Crypto API.
Related Developer Utilities
Frequently paired tools in the Encoding & Crypto workflow.
Base64 Encoder & Decoder
Encode and decode text, hex, URL-safe Base64, and convert images/files to Data URIs.
Cryptographic Hash & Checksum Generator
Generate SHA-256, SHA-512, SHA-1, MD5, and HMAC hashes locally using Web Crypto API.
URL Encoder & Decoder
Encode and decode URLs, query parameters, and reserved characters with RFC 3986 compliance.