JWT Inspector

Decode JWT headers and payloads, verify HMAC signatures with an expected algorithm, and check expiry, not-before, issuer and audience in your browser.

Paste a compact JWT to inspect its header and payload. Select your expected HS256, HS384 or HS512 algorithm and enter a UTF-8 secret for a signature check. Expiry, not-before, issuer and audience are separate diagnostics, not an authorization decision.

Last updated:

JWT Decoder & Parser — Free Online JSON Web Token Tool. Decode JWT headers and payloads, verify HMAC signatures with an expected algorithm, and check expiry, not-before, issuer and audience in your browser.

Inspect compact, unencrypted JSON Web Tokens with this JWT decoder . Decoding reveals the header and payload but does not establish authenticity.

The signature check requires an independently selected HS256, HS384 or HS512 algorithm and a supplied UTF-8 secret. A mismatched algorithm, unsupported critical extension or public-key algorithm is never reported as verified.

The claims checks compare exp and nbf against your device clock every second, with 0–300 seconds of tolerance. Optional issuer and audience comparisons are exact and case-sensitive; audience can be a string or an array of strings.

Missing time claims, invalid NumericDates and skipped comparisons have separate states. These checks do not establish key ownership, revocation status, token purpose or application authorization.

Frequently asked questions

Does decoding a JWT verify its signature?

No. Decoding only exposes its JSON header and payload. Choose your expected HS256, HS384 or HS512 algorithm and enter a UTF-8 secret to run the separate HMAC signature check. Public-key signatures are not verified here.

How are expiration and not-before checked?

The device clock refreshes every second. exp passes only before its NumericDate plus tolerance; nbf passes once the clock plus tolerance reaches its NumericDate. Tolerance must be a whole number from 0 to 300 seconds. Missing claims are shown as not present, and string or null dates fail.

How do issuer and audience comparisons work?

Enter the issuer or audience your application expects. Comparisons are exact and case-sensitive. Audience may be one string or an array of strings. Blank expected values skip those comparisons; they are not reported as passed.

What example can I try?

Load the public example, choose HS256 and enter your-256-bit-secret. The signature matches, while exp and nbf are not present. This example secret is for demonstration only.

Are my token and secret saved or shared?

Inputs stay in memory and are cleared when leaving or reloading. Copy tool link includes no token or secret. Copy header or payload explicitly places that decoded content on your clipboard. The page displays ads, so use test credentials.

Do passing checks mean this token is authorized?

No. This is a diagnostic tool, not an authorization service. It does not establish key ownership, revocation status, intended token purpose or application permissions. Verification belongs in the receiving application.

How to use this online tool

JWT Decoder & Parser — Free Online JSON Web Token Tool is designed for fast browser workflows when you need to format, validate, convert, decode, encode, generate, or inspect data without opening a heavy desktop app. Start with the input field or visible options, review the result, then copy or download the output for the next step.

Private processing in your browser

JWT Decoder & Parser — Free Online JSON Web Token Tool keeps the normal processing step local in your browser. That is useful for code snippets, tokens, documents, configuration values, text samples, and other material that should not be sent to a remote service unless you explicitly choose to share it.

When this tool is useful

Use JWT Decoder & Parser — Free Online JSON Web Token Tool for repeatable developer tasks, technical documentation, QA checks, quick conversions, debugging, content cleanup, and internal team workflows. The page focuses on clear inputs, immediate feedback, and output that is easy to reuse in code, reports, tickets, emails, or notes.

Practical tips

Before copying the final result, check important details such as spacing, casing, filenames, encoding, token structure, line breaks, or output format. Small checks prevent mistakes when the result is reused in source code, API requests, documentation, spreadsheets, or shared files.