Utility tools / JWT Inspector

Understand what your token says.

Read token claims, understand expiration, and inspect signatures.

01 / JWT inspectorDecoded ≠ verified

Three segments. Different responsibilities.

Read the claims, check their dates, and keep signature verification separate.

01 / Header02 / Payload03 / Signature
Paste header.payload.signature. A decoded signed JWT is readable; it is not encrypted.

Header / metadata

{
  "alg": "HS256",
  "typ": "JWT"
}

alg names the signing algorithm. kid is a key identifier; it is not a key or proof of identity.

Payload / claims

{
  "sub": "labs-demo-42",
  "name": "Alex Morgan",
  "role": "designer",
  "iat": 1790812800,
  "nbf": 1790812800,
  "exp": 1917043200,
  "iss": "https://example.com",
  "aud": "labs-demo"
}

Claims describe a subject and policy. Reading them does not make them trustworthy.

Claim timeline / UTC

iat / Issued atAwaiting time check1790812800 Unix seconds
nbf / Not beforeAwaiting time check1790812800 Unix seconds
exp / ExpirationAwaiting time check1917043200 Unix seconds

Preparing the time check… Leeway adjusts exp/nbf comparisons; it does not verify a signature.

Signature verification / HS256

Not verified
Use the same UTF-8 secret as the issuer. This tool accepts HS256 only.
Algorithm: HS256

HMAC-SHA256 uses a shared secret. Verification checks the original encoded header and payload against the supplied signature.

A matching signature proves consistency with the provided key. It does not establish a trusted issuer, validate the audience, apply permissions, or check revocation.

Signature size: 32 bytes.
Understand the claims
subSubject

Who or what the token identifies. Meaning is assigned by the issuer.

"labs-demo-42"
nameCustom claim

Application-defined data. Its meaning and authorization rules depend on the issuer and recipient.

"Alex Morgan"
roleCustom claim

Application-defined data. Its meaning and authorization rules depend on the issuer and recipient.

"designer"
iatIssued at

NumericDate: when the token was issued. It is not an expiration time.

1790812800
nbfNot before

NumericDate: the token should not be accepted before this time.

1790812800
expExpiration

NumericDate: seconds since the Unix epoch. The token should no longer be accepted at or after this time.

1917043200
issIssuer

Who issued the token. Compare it with your expected issuer; decoding it does not establish that identity.

"https://example.com"
audAudience

Intended recipient or recipients. Your application must check that it is one of them.

"labs-demo"

Before trusting a token

Base64URL is encoding, not encryption. Do not put confidential information in a readable payload. A valid expiration date alone cannot prove a token is authentic.

Use an explicit algorithm allowlist. Never accept alg:none for authentication. A key ID is a lookup hint, not permission to fetch an arbitrary key. Validate issuer, audience, time claims, and application rules after checking the signature.

More from Labs

Utility catalogue

Loading more tools…