Developer ToolsPopular100% Client-Side Private

Free Online JWT Decoder, Inspector & Verifier

Enterprise-grade online JWT Decoder, Debugger, and Signature Verifier. Paste any JSON Web Token (or Bearer token) to decode header, payload, and signature segments in real-time. Features intelligent Unix timestamp conversion for exp, iat, and nbf claims with live expiration status countdowns, RFC 7519 standard claim tooltips, critical 'alg: none' vulnerability alerts, and 100% private in-browser signature verification via Web Crypto API. Zero server transmissions — your authentication tokens remain completely confidential.

100% Client-Side Privacy: Tokens and secrets are decoded and verified entirely in your browser. Nothing is ever sent to a server or stored in cookies.
Zero Server Logs
Presets:
Encoded JWT Token
Segment Color LegendTotal: 480 B (480 chars)
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfOTQ4MjcxMDM5IiwibmFtZSI6IkFsZXggTW9yZ2FuIiwiZW1haWwiOiJhbGV4Lm1vcmdhbkBleGFtcGxlLmNvbSIsInJvbGUiOiJhZG1pbiIsInBlcm1pc3Npb25zIjpbInJlYWQ6cmVwb3J0cyIsIndyaXRlOnNldHRpbmdzIiwiYWRtaW46YWxsIl0sImlhdCI6MTczNTcwODgwMCwibmJmIjoxNzM1NzA4ODAwLCJleHAiOjE5MzU3MDg4MDAsImlzcyI6Imh0dHBzOi8vYXV0aC50cnlhbmR0b29sLmNvbSIsImF1ZCI6Imh0dHBzOi8vYXBpLnRyeWFuZHRvb2wuY29tIiwidGkiOiJqd3RfdG9rXzliMmU4YTFmIn0.kE1vT9-xY7r5x7_L8W0xY-Q2n4r6v8x0Z2b4c6e8g0i
Header
36 B
Payload
399 B
Signature
43 B

Verify Signature (Optional)

100% In-Browser

Verify HMAC tokens (HS256/384/512) with your secret or RSA/ECDSA tokens (RS256/ES256) with a public key.

Enter HMAC secret or Public Key to verify signature client-side.

Timestamp Intelligence & Health

Real-time evaluation against current local time
Valid & Active
Expiration (exp)in 1677d 17h
May 5, 2031, 12:53:20 AM
UTC: Mon, 05 May 2031 00:53:20 GMT
Unix: 1935708800
Issued At (iat)637d 1h ago
Jan 1, 2025, 5:20:00 AM
UTC: Wed, 01 Jan 2025 05:20:00 GMT
Unix: 1735708800
Not Before (nbf)637d 1h ago
Jan 1, 2025, 5:20:00 AM
UTC: Wed, 01 Jan 2025 05:20:00 GMT
Unix: 1735708800
Header (Algorithm & Token Type)
{
  "alg": "HS256",
  "typ": "JWT"
}
Payload (Claims & Data)
subSubject
RFC 7519 §4.1.2string

Identifies the user, identity, or entity that is the subject of the token (e.g. user ID).

usr_948271039
name
Custom Claimstring
Alex Morgan
email
Custom Claimstring
alex.morgan@example.com
role
Custom Claimstring
admin
permissions
Custom Claimobject
[
  "read:reports",
  "write:settings",
  "admin:all"
]
iatIssued At
RFC 7519 §4.1.6number

Unix epoch timestamp identifying when this JWT was created and issued.

Jan 1, 2025, 5:20:00 AM(637d 1h ago)
nbfNot Before
RFC 7519 §4.1.5number

Unix epoch timestamp identifying the time before which this token must not be accepted.

Jan 1, 2025, 5:20:00 AM(637d 1h ago)
expExpiration Time
RFC 7519 §4.1.4number

Unix epoch timestamp identifying when this token expires and must no longer be accepted.

May 5, 2031, 12:53:20 AM(in 1677d 17h)
issIssuer
RFC 7519 §4.1.1string

Identifies the principal/authority that issued the JWT (e.g. auth0.com, accounts.google.com).

https://auth.tryandtool.com
audAudience
RFC 7519 §4.1.3string

Identifies the recipients/APIs that the JWT is intended for. The recipient must verify this.

https://api.tryandtool.com
ti
Custom Claimstring
jwt_tok_9b2e8a1f
Signature Verification Segment
kE1vT9-xY7r5x7_L8W0xY-Q2n4r6v8x0Z2b4c6e8g0i

The cryptographic signature is created by hashing the Base64Url-encoded header and payload with your secret or private key.

Key Features & Capabilities

  • Real-time instant decoding as you type or paste with automatic 'Bearer ' prefix stripping
  • Color-coded segment breakdown matching RFC standards (Header: Rose, Payload: Violet, Signature: Cyan)
  • Timestamp Intelligence: converts exp, iat, and nbf to local time, UTC, and ISO 8601 with live expiration countdown
  • Live Health Status Badge: dynamically flags Valid & Active, Expired, Not Yet Valid, or Missing Expiration tokens
  • RFC 7519 standard claim explanations and tooltips (iss, sub, aud, exp, nbf, iat, jti, alg, typ, kid)
  • Dual Payload View: interactive visual Claims Inspector and syntax-highlighted raw JSON code block
  • 100% Client-Side Cryptographic Verification via Web Crypto API for HMAC (HS256/384/512) and RSA/ECDSA (RS256/ES256)
  • Security Auditing: instant critical warning when insecure 'alg: none' algorithm or missing signatures are detected
  • Graceful JWE (JSON Web Encryption) 5-segment detection with clear encryption explanation
  • Exact byte and character size breakdown for total token and each individual segment
  • 1-click copy buttons for Header, Payload, Signature, clean raw token, or formatted JSON
  • Zero server transmission and zero local storage persistence for maximum security and confidentiality

Security & Performance Guarantee

Try & Tool runs this utility directly in your browser. No files, passwords, or data payloads are ever transmitted to or stored on our servers.

Client-Side Only•Zero Logging•Free Forever
Guide & Documentation

How to Use JWT Decoder & Inspector Online

JSON Web Tokens (JWT) are the industry-standard method (RFC 7519) for transmitting authentication and authorization claims between web clients, microservices, and identity providers like Auth0, AWS Cognito, Firebase, and Keycloak. Try & Tool's Online JWT Decoder & Inspector provides a secure, high-performance workspace to inspect token anatomy, decode header and payload claims, track expiration dates, audit cryptographic parameters, and verify signatures with 100% browser-side privacy.

Step 1

Enter Input

Paste your code, upload your file, or enter raw data.

Step 2

Instant Processing

Real-time browser evaluation computes results with zero latency.

Step 3

Copy or Export

Download formatted assets or copy clean output with one click.

1. The Anatomy of a JSON Web Token (RFC 7519)

A standard signed JSON Web Token (JWS) consists of three base64url-encoded parts separated by period (.) delimiters: Header, Payload, and Signature. Each segment serves a dedicated cryptographic and identity role.

  • Header (Red/Rose): Defines the token type (usually 'JWT') and the signing algorithm ('alg', e.g. HS256, RS256, ES256).
  • Payload (Violet/Purple): Contains the claims—statements about the user, permissions, issuer, and token lifecycle.
  • Signature (Cyan/Teal): Generated by hashing the encoded Header and Payload with a secret or private key to ensure tamper-proof integrity.
// Standard JWT Structure:
header.payload.signature

// 1. Decoded Header:
{ "alg": "HS256", "typ": "JWT" }

// 2. Decoded Payload:
{ "sub": "usr_10293", "name": "Jane Doe", "role": "admin", "exp": 1757000000 }

// 3. Signature Calculation (HMAC SHA-256):
HMACSHA256(base64UrlEncode(header) + "." + base64UrlEncode(payload), secret)

2. RFC 7519 Standard Registered Claims Reference

The IETF RFC 7519 specification defines a set of registered standard claims that provide uniform metadata across modern authentication and API ecosystems.

  • iss (Issuer): Identifies the authority that created the token (e.g. https://auth0.com or https://accounts.google.com).
  • sub (Subject): The unique identifier for the user or entity the token represents (e.g. user ID or service UUID).
  • aud (Audience): The intended recipients or backend APIs that should accept this token.
  • exp (Expiration Time): Unix epoch timestamp marking when the token must no longer be accepted by APIs.
  • nbf (Not Before): Unix epoch timestamp specifying the earliest time at which the token becomes active.
  • iat (Issued At): Unix epoch timestamp indicating exactly when the token was signed and issued.
  • jti (JWT ID): A unique cryptographic identifier for the token, useful for blacklisting and preventing replay attacks.

3. Timestamp Intelligence & Expiration Auditing

Expired tokens are the #1 cause of sudden 401 Unauthorized errors in frontend applications and microservices. Our Timestamp Intelligence engine automatically evaluates exp, iat, and nbf against your current local clock.

  • Converts raw Unix epoch integers into local system time, UTC string, and ISO 8601 formatting.
  • Calculates human-readable relative time (e.g. 'Expires in 2 hours 15 mins' or 'Expired 3 days ago').
  • Displays live visual health status badges: Valid & Active, Token Expired, Not Yet Valid, or Missing Expiration.

4. Client-Side Cryptographic Signature Verification

Unlike server-dependent tools that require uploading your private signing secrets to a remote backend, Try & Tool leverages the browser's native Web Crypto API (SubtleCrypto) to verify signatures completely inside your browser sandbox.

  • HMAC Symmetric Verification: Test HS256, HS384, and HS512 tokens with raw text secrets or Base64-encoded binary keys.
  • RSA / ECDSA Asymmetric Verification: Test RS256, RS384, RS512, ES256, and ES384 signatures using standard X.509 / SPKI PEM public keys.
  • Real-time validation feedback confirms whether the signature matches or if the token has been tampered with.

5. Critical Security Vulnerabilities in JWT Implementations

Understanding common JWT architectural pitfalls helps development teams build secure authentication systems and protect user credentials.

  • The 'alg: none' Exploit: If an API server fails to enforce expected algorithms, attackers can alter the payload and set 'alg' to 'none' to bypass authentication entirely.
  • Weak HMAC Secrets: Using short or dictionary-based HMAC secrets allows attackers to crack signatures offline via brute-force dictionary tools.
  • Storing Sensitive Data in Payloads: Because standard JWT payloads are merely Base64Url-encoded and unencrypted, storing passwords, API tokens, or PII leaks data to anyone who intercepts the token.

JSON Web Tokens (JWS) vs. JWE vs. Traditional Session Cookies

CharacteristicJWT / JWS (Signed)JWE (Encrypted)Session Cookies (Server-Side)
RFC StandardRFC 7519 / RFC 7515RFC 7516RFC 6265
Structure3 segments (Header.Payload.Sig)5 segments (Encrypted data)Opaque session ID string
Payload VisibilityPublicly readable (Base64Url)Encrypted (Requires private key)Hidden on database/Redis server
State ManagementStateless (Self-contained)Stateless (Self-contained)Stateful (Server database lookup required)
Verification MethodCryptographic signature checkDecryption with secret/private keyDatabase / Redis session lookup
Best Use CaseMicroservices, REST APIs, OAuth 2.0Confidential claims, PII data in tokenMonolithic web apps, banking sessions
Questions & Answers

Frequently Asked Questions about JWT Decoder & Inspector

Yes, 100%. Our JWT Decoder & Inspector executes entirely client-side in your web browser using native JavaScript and the browser's Web Crypto API (crypto.subtle). Your tokens, payloads, API secrets, and cryptographic keys are never sent over the network, logged to a server, or stored in cookies or localStorage.