JWT Inspector
Decode a JSON Web Token and see what every claim means.
- Free
- No signup
- Nothing uploaded
- No watermark
Header
{
"alg": "HS256",
"typ": "JWT"
}Payload
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}Header fields
- algAlgorithm — how the signature was made
- HS256
- typType — almost always JWT
- JWT
Payload claims
- subSubject — who the token is about, usually a user id
- 1234567890
- name
- John Doe
- iatIssued at — when the token was created
- 15162390222018-01-18 01:30:22 UTC
How to Decode a JWT and Read Its Claims
A JSON Web Token looks like three blobs of letters joined by dots. When a login breaks or an API returns 401, the first question is usually what is actually inside the token. Paste it here and you get the header and payload as tidy JSON, plus a plain explanation of every claim.
Timestamps such as exp, iat and nbf are shown as real dates in UTC, and an expired token gets a clear red warning. Decoding happens in the page as you paste, so a production token from your own app is not sent to anyone.
No software to install Free Works on any device
Steps to Inspect a JSON Web Token
-
1. Paste your token
Replace the example in the Token box with your own JWT. Copy it from a browser’s developer tools, an Authorization header or your app’s logs. The Example button puts the sample back.
-
2. Read the header and payload
Two panels show the decoded JSON. The header names the signing algorithm and type; the payload holds the claims about the user and the session.
-
3. Check what each claim means
The What the claims mean list explains standard fields such as iss, sub, aud and exp in plain words, and turns time claims into dates you can read.
-
4. Watch for the expiry warning
If the exp time is already in the past by your device clock, a red note tells you the token has expired and a correct server will reject it.
What Is a JWT?
A JWT is a compact way for a server to hand a client a set of facts, called claims, that it can later prove it issued. It has three Base64URL parts: a header, a payload and a signature. The first two are plain JSON that anyone can decode; the signature is what stops them being changed.
That split matters. A JWT is signed, not encrypted, so the payload is readable by anyone who holds the token. This inspector proves the point by reading it without any secret. It does not check the signature itself; that needs the key the token was signed with.
Why Use Security and Crypto Tools Locally?
Hashes, keys, tokens and passwords are exactly the things you should not paste into a stranger’s server. Here they are made and checked inside your browser, so secrets stay on the machine in front of you.
“A secret generated on your own device stays yours.”
- Strong random passwords
- Keys generated on your device
- Two-factor codes for testing
- Files checked against checksums
- Hashes in every common algorithm
- JWTs decoded and checked
- Security headers written for you
- No secrets sent anywhere
Popular Uses for Hash and Key Generators
Developers and careful users reach for these during everyday security work.
- New passwords Generate a long random password or passphrase for a new account.
- Verifying downloads Hash a file with SHA-256 and compare it with the value the publisher lists.
- Debugging logins Decode a JWT to see its claims and check the signature with your secret.
- SSH and API keys Create an RSA or Ed25519 key pair or an API key for a new service.
- Website headers Write a Content Security Policy and other security headers for a web server.
- Testing two-factor login Generate TOTP codes and secrets to test an authenticator setup during development.
- Script integrity Make an SRI hash so a browser can tell if a CDN script was changed.
- Password strength Measure how many guesses a password would take, using its entropy.
What the JWT Inspector Shows
Pretty header and payload
Both parts decoded and indented as JSON in separate panels, so nested claims are easy to follow.
Claim explanations
Registered claims such as iss, sub, aud, exp, nbf and iat come with a short note on what each one is for.
Readable timestamps
Unix times inside exp, iat and nbf are shown next to a UTC date and time, so you can see when a session started and ends.
Expiry check
The page compares exp with your device clock and flags a token that has already expired.
Clear error messages
A token with the wrong number of parts or broken Base64 gets a message that says what is wrong instead of a blank screen.
Why Use ToolXkit for JWT Inspector?
Your files stay with you
Everything runs inside your browser. Nothing you open or type is uploaded to a server.
Free, with no catch
No signup, no watermark and no daily limit on how often you use it.
Fast
Results appear in seconds, because nothing has to travel over the internet and back.
Works on any device
Use it on a computer, tablet or phone, in Chrome, Edge, Firefox or Safari.
Nothing to install
No app, no extension and no desktop program. Open the page and start.
Made for real people
Plain words and clear buttons, built by one developer who wanted tools like this to exist.
Crypto Tools for Different Users
Web developers
Create security headers, SRI hashes and JWTs while building and testing apps.
System administrators
Generate SSH keys, check fingerprints and verify file checksums on the go.
Security testers
Decode tokens, inspect PEM files and test HMAC signatures without extra tooling.
Computer science students
See how hashing, encryption and key pairs behave by trying them yourself.
Everyday users
Make strong passwords and passphrases that are never sent over the internet.
IT teams
Create API keys and OAuth values for new integrations in a safe place.
Best Times to Generate a Key or Hash
Local crypto tools make sense when you are:
- Setting up a new server
- Creating a strong password
- Checking a downloaded installer
- Debugging a sign-in problem
- Adding security headers to a site
- Testing an authenticator app
- Learning how encryption works
- Rotating an old API key
Tips for Debugging JWTs
-
Never put passwords, card numbers or other private data in a payload. Anyone with the token can read it, as this page shows.
-
If a token is rejected but looks valid, compare exp and nbf with the server clock. A few minutes of clock drift is a common cause.
-
Paste only the token itself. Remove the word Bearer and any quotes that came along from a header or JSON response.
-
Check the alg field in the header. A token signed with a different algorithm from the one your server expects will fail verification.
-
Look at aud and iss when a token works on one service but not another. They say who issued the token and who it was meant for.
Frequently Asked Questions
Answers to common questions about this tool.
Is it safe to paste a real JWT here?
The token is decoded by JavaScript inside this tab and is not sent to a server. Even so, a live token is a key to an account until it expires, so treat it with care and avoid pasting tokens for systems you do not own.
Does this verify the JWT signature?
No. This page decodes and explains the contents only. Checking the signature needs the secret or public key that signed it, and a decoded payload tells you nothing about whether it is genuine.
Why can anyone read my JWT payload?
The header and payload are only Base64URL encoded, which is a way of writing bytes as text, not a form of encryption. The signature protects against changes, not against reading. Use encrypted tokens (JWE) if the contents must stay private.
What does exp mean in a JWT?
exp is the expiry time, written as seconds since 1 January 1970 in UTC. After that moment the token must be rejected. This page shows it as a normal date and warns you when it has already passed.
Why does my token show an error?
A JWT needs three parts separated by dots, and the first two must decode to valid JSON. Extra spaces, a missing section or a cut-off copy are the usual causes. Copy the token again from the source and paste it without any surrounding text.
Are the keys and passwords made here truly random?
They come from the browser’s built-in secure random number generator, the same source used for encrypted connections. That is suitable for passwords, keys and tokens.
Does JWT Inspector send my secrets to a server?
No. Everything is worked out locally, and what you type or generate is neither uploaded nor logged. For real production keys, it is still wise to generate them on the machine where they will be used.
Is JWT Inspector free for commercial projects?
Yes. Use it for personal, work or client projects at no cost and without an account. What you generate belongs to you, and the site keeps no copy.
Can a hash be reversed to get the original text?
No. A hash is one-way. Short or common passwords can still be guessed by trying many candidates, which is why a long, random password matters more than the hash you pick.
Further reading
- Hash Functions (NIST) NIST’s page on approved hash functions such as SHA-2 and SHA-3.
- RFC 7519: JSON Web Token (IETF) The standard that defines JSON Web Tokens and the claims inside them.
- RFC 6238: TOTP (IETF) The standard behind the six-digit codes shown in authenticator apps.
More Security & Crypto Tools
Other free tools for the same kind of job.
- Adler-32 Calculator Work out the Adler-32 checksum used inside zlib. Open tool
- AES Encrypt & Decrypt Encrypt or decrypt text with a password. Open tool
- AES Key Generator Generate a random AES-128 or AES-256 key. Open tool
- API Key Generator Generate API keys with a readable prefix and real entropy behind them. Open tool
- Bulk Password Generator Generate hundreds of strong passwords at once, with no modulo bias. Open tool
- Checksum Calculator CRC-32, CRC-16 and Adler-32 for any text or file, side by side. Open tool
- CORS Header Generator Build CORS headers, with the wildcard-plus-credentials trap caught. Open tool
- CRC16 Calculator Work out CRC-16, both the ARC and CCITT variants. Open tool
- CRC32 Calculator Work out the CRC-32 checksum used by ZIP, PNG and gzip. Open tool