Skip to content
All tools

JWT Inspector

Available

Decode token structure, inspect registered claims and understand time-based state without uploading the token anywhere.

Runs locally. Your token never leaves this browser.

Encoded token

Compact JWS structure: header.payload.signature

HEADER
PAYLOAD
SIGNATURE

Algorithm

HS256

typ=JWT

Token time

Time window active

Based only on exp / nbf

SIGNATURE

Present · unverified

12 chars

Expires

2100-01-01T00:00:00.000Z

Decoded header

JSON

Decoded payload

JSON

Registered claims

Subject sub
1234567890
Expires at exp
4102444800 · 2100-01-01T00:00:00.000Z
Issued at iat
1760000000 · 2025-10-09T08:53:20.000Z

Security notes

Signature is present, but it has not been cryptographically verified.

Understand what is being inspected

JWT Inspector reports structure and claim metadata. Use the info controls as a quick legend when a field is unfamiliar. None of these values should be trusted until the token signature and expected issuer/audience are verified by the receiving application.

alg

Signing algorithm

exp

Expiration Time

nbf

Not Before

iat

Issued At

iss

Issuer

sub

Subject

aud

Audience

jti

JWT ID

What JWT Inspector checks

The inspector decodes the Base64URL header and payload, exposes the declared algorithm and token type, and interprets registered claims such as exp, nbf, iat, iss, sub, aud and jti. Time state is evaluated against the current browser clock.

Decoding is not verification

Anyone can Base64URL-decode a JWT. Reading its claims does not prove who issued it or whether it was modified. This version deliberately reports the signature as unverified instead of creating a false sense of authenticity.