Utility tools / JWT Inspector
Understand what your token says.
Read token claims, understand expiration, and inspect signatures.
Three segments. Different responsibilities.
Read the claims, check their dates, and keep signature verification separate.
Header / metadata
{
"alg": "HS256",
"typ": "JWT"
}alg names the signing algorithm. kid is a key identifier; it is not a key or proof of identity.
Payload / claims
{
"sub": "labs-demo-42",
"name": "Alex Morgan",
"role": "designer",
"iat": 1790812800,
"nbf": 1790812800,
"exp": 1917043200,
"iss": "https://example.com",
"aud": "labs-demo"
}Claims describe a subject and policy. Reading them does not make them trustworthy.
Claim timeline / UTC
Preparing the time check… Leeway adjusts exp/nbf comparisons; it does not verify a signature.
Signature verification / HS256
Not verifiedHMAC-SHA256 uses a shared secret. Verification checks the original encoded header and payload against the supplied signature.
A matching signature proves consistency with the provided key. It does not establish a trusted issuer, validate the audience, apply permissions, or check revocation.
Signature size: 32 bytes.Understand the claims
subSubjectWho or what the token identifies. Meaning is assigned by the issuer.
"labs-demo-42"
nameCustom claimApplication-defined data. Its meaning and authorization rules depend on the issuer and recipient.
"Alex Morgan"
roleCustom claimApplication-defined data. Its meaning and authorization rules depend on the issuer and recipient.
"designer"
iatIssued atNumericDate: when the token was issued. It is not an expiration time.
1790812800
nbfNot beforeNumericDate: the token should not be accepted before this time.
1790812800
expExpirationNumericDate: seconds since the Unix epoch. The token should no longer be accepted at or after this time.
1917043200
issIssuerWho issued the token. Compare it with your expected issuer; decoding it does not establish that identity.
"https://example.com"
audAudienceIntended recipient or recipients. Your application must check that it is one of them.
"labs-demo"
Before trusting a token
Base64URL is encoding, not encryption. Do not put confidential information in a readable payload. A valid expiration date alone cannot prove a token is authentic.
Use an explicit algorithm allowlist. Never accept alg:none for authentication. A key ID is a lookup hint, not permission to fetch an arbitrary key. Validate issuer, audience, time claims, and application rules after checking the signature.
More from Labs
Utility catalogueLoading more tools…