Skip to content
Shrake DevTools
  • JSON FormatterData & Format
  • JSON ValidatorData & Format
  • JSON MinifierData & Format
  • JSON ↔ YAML ConverterData & Format
  • XML FormatterData & Format
  • Base64 Encoder / DecoderData & Format
  • URL Encoder / DecoderData & Format
  • JWT InspectorData & Format
↑ ↓ to navigate↵ to openEsc to close

JWT Inspector

Decode a JWT header and payload, inspect claims and check expiry. Decoding does not verify the signature.

Runs locally in your browser. Your input is not uploaded.Free, no sign-up

Encoded token

How to use the JWT Inspector

  1. Paste a JSON Web Token, with or without the Bearer prefix, or click Sample.
  2. See the header, the payload and every claim explained, with dates in readable form.
  3. The status shows whether the token has expired, isn't valid yet, or never expires.

Decoding is not verifying

A JWT's header and payload are only Base64url-encoded, so anyone can read them, and anyone can create a token with any contents. What makes a token trustworthy is its signature, checked by your server with the right secret or public key. This tool decodes tokens but doesn't verify signatures. Never trust a token just because it decodes.

What the parts mean

  • Header: the signing algorithm (alg, e.g. HS256 or RS256), the token type and often a key ID (kid).
  • Payload: the claims, such as who the token is about (sub), who issued it (iss), who it's for (aud) and when it expires (exp).
  • Signature: proves the header and payload weren't changed, if it verifies.

Frequently asked questions

Is it safe to paste a real token here?

The token is decoded entirely in your browser and never sent anywhere. Still, a valid token is a credential: avoid pasting live production tokens into any website, and prefer expired or test tokens.

Why does it say "No expiry"?

The token has no exp claim, so it stays valid until the signing key changes. Tokens should normally be short-lived.

What is alg "none"?

An unsigned token. Accepting these is a well-known vulnerability: an attacker can change any claim. Servers should reject them.

What about encrypted tokens (JWE)?

Tokens with five parts are encrypted. Their payload can only be read with the recipient's private key, so they can't be decoded here.