JWT Decoder & Inspector

Security

Decode and inspect JSON Web Tokens (Header, Payload, Claims, Expiration) with client-side verification.

Paste Encoded JWT Token
● Header● Payload● Signature
Token Status: ACTIVE(Expires in 1254 days)
Decoded Header (Algorithm & Token Type)
JOSE Header
{
  "alg": "HS256",
  "typ": "JWT"
}
UTF-8•100% Local Sandbox
4 lines • 36 Bytes
Decoded Payload (Claims & Subject Data)
Claims
{
  "sub": "1234567890",
  "name": "Alex Developer",
  "admin": true,
  "iat": 1516239022,
  "exp": 1899849900
}
UTF-8•100% Local Sandbox
7 lines • 112 Bytes

Local Signature Verification

Verify HMAC HS256 signatures client-side using Web Crypto API. Secret never leaves your machine.

About JWT Decoder & Inspector

A JSON Web Token (JWT) is a compact, URL-safe means of representing claims between two parties. A token consists of three Base64URL-encoded parts separated by dots: the Header (algorithm and token type), the Payload (user claims and expiration timestamp), and the cryptographic Signature.

Zero-Upload Privacy Guarantee

Never paste production Bearer tokens or admin session JWTs into unknown third-party websites. Other online tools might log tokens and compromise user accounts. DevTools runs purely in your browser memory.

Client-Side Sandbox● 100% Air-Gapped

Key Capabilities & Features

Color-coded visual representation of Header, Payload, and Signature
Automatic parsing of standard claims (iat, exp, nbf, iss, sub, aud)
Live expiration calculator showing time remaining or elapsed since expiry
Local HMAC signature verification using the browser's native Web Crypto API
Formatted JSON output with one-click copy for Header and Payload

How to use this JWT decoder

1

Paste JWT Token

Paste any Bearer or ID token into the input field. Colors separate Header, Payload, and Signature.

2

Inspect Claims & Timestamps

Review standard claims like 'exp' (expiration), 'iat' (issued at), 'iss' (issuer), and 'sub' (subject).

3

Check Expiration Status

Notice the live badge displaying whether the token is currently valid or expired, with relative countdown.

4

Test Signature Locally (Optional)

Enter your HMAC secret (for HS256/384/512) to verify signature validity directly using Web Crypto API.

Frequently Asked Questions

Decoding simply unpacks the Base64URL claims so you can read them. To verify authenticity, the signature must be validated against the signing secret or public key.