ToolXkit Icon

JWT Inspector

Decode a JSON Web Token and see what every claim means.

  • Free
  • No signup
  • Nothing uploaded
  • No watermark

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}

Header fields

algAlgorithm — how the signature was made
HS256
typType — almost always JWT
JWT

Payload claims

subSubject — who the token is about, usually a user id
1234567890
name
John Doe
iatIssued at — when the token was created
15162390222018-01-18 01:30:22 UTC

How to Decode a JWT and Read Its Claims

JWT Inspector: before and after TEXT A YOUR INPUT JWT INSPECTOR DONE A RESULT

A JSON Web Token looks like three blobs of letters joined by dots. When a login breaks or an API returns 401, the first question is usually what is actually inside the token. Paste it here and you get the header and payload as tidy JSON, plus a plain explanation of every claim.

Timestamps such as exp, iat and nbf are shown as real dates in UTC, and an expired token gets a clear red warning. Decoding happens in the page as you paste, so a production token from your own app is not sent to anyone.

No software to install Free Works on any device

Steps to Inspect a JSON Web Token

  1. 1. Paste your token

    Replace the example in the Token box with your own JWT. Copy it from a browser’s developer tools, an Authorization header or your app’s logs. The Example button puts the sample back.

  2. 2. Read the header and payload

    Two panels show the decoded JSON. The header names the signing algorithm and type; the payload holds the claims about the user and the session.

  3. 3. Check what each claim means

    The What the claims mean list explains standard fields such as iss, sub, aud and exp in plain words, and turns time claims into dates you can read.

  4. 4. Watch for the expiry warning

    If the exp time is already in the past by your device clock, a red note tells you the token has expired and a correct server will reject it.

Try it now

What Is a JWT?

A JWT is a compact way for a server to hand a client a set of facts, called claims, that it can later prove it issued. It has three Base64URL parts: a header, a payload and a signature. The first two are plain JSON that anyone can decode; the signature is what stops them being changed.

That split matters. A JWT is signed, not encrypted, so the payload is readable by anyone who holds the token. This inspector proves the point by reading it without any secret. It does not check the signature itself; that needs the key the token was signed with.

Why Use Security and Crypto Tools Locally?

Hashes, keys, tokens and passwords are exactly the things you should not paste into a stranger’s server. Here they are made and checked inside your browser, so secrets stay on the machine in front of you.

“A secret generated on your own device stays yours.”
  • Strong random passwords
  • Keys generated on your device
  • Two-factor codes for testing
  • Files checked against checksums
  • Hashes in every common algorithm
  • JWTs decoded and checked
  • Security headers written for you
  • No secrets sent anywhere

Popular Uses for Hash and Key Generators

Developers and careful users reach for these during everyday security work.

  • New passwords Generate a long random password or passphrase for a new account.
  • Verifying downloads Hash a file with SHA-256 and compare it with the value the publisher lists.
  • Debugging logins Decode a JWT to see its claims and check the signature with your secret.
  • SSH and API keys Create an RSA or Ed25519 key pair or an API key for a new service.
  • Website headers Write a Content Security Policy and other security headers for a web server.
  • Testing two-factor login Generate TOTP codes and secrets to test an authenticator setup during development.
  • Script integrity Make an SRI hash so a browser can tell if a CDN script was changed.
  • Password strength Measure how many guesses a password would take, using its entropy.

What the JWT Inspector Shows

Pretty header and payload

Both parts decoded and indented as JSON in separate panels, so nested claims are easy to follow.

Claim explanations

Registered claims such as iss, sub, aud, exp, nbf and iat come with a short note on what each one is for.

Readable timestamps

Unix times inside exp, iat and nbf are shown next to a UTC date and time, so you can see when a session started and ends.

Expiry check

The page compares exp with your device clock and flags a token that has already expired.

Clear error messages

A token with the wrong number of parts or broken Base64 gets a message that says what is wrong instead of a blank screen.

Why Use ToolXkit for JWT Inspector?

Your files stay with you

Everything runs inside your browser. Nothing you open or type is uploaded to a server.

Crypto Tools for Different Users

Web developers

Create security headers, SRI hashes and JWTs while building and testing apps.

System administrators

Generate SSH keys, check fingerprints and verify file checksums on the go.

Security testers

Decode tokens, inspect PEM files and test HMAC signatures without extra tooling.

Computer science students

See how hashing, encryption and key pairs behave by trying them yourself.

Everyday users

Make strong passwords and passphrases that are never sent over the internet.

IT teams

Create API keys and OAuth values for new integrations in a safe place.

Best Times to Generate a Key or Hash

Local crypto tools make sense when you are:

  • Setting up a new server
  • Creating a strong password
  • Checking a downloaded installer
  • Debugging a sign-in problem
  • Adding security headers to a site
  • Testing an authenticator app
  • Learning how encryption works
  • Rotating an old API key

Tips for Debugging JWTs

  1. Never put passwords, card numbers or other private data in a payload. Anyone with the token can read it, as this page shows.

  2. If a token is rejected but looks valid, compare exp and nbf with the server clock. A few minutes of clock drift is a common cause.

  3. Paste only the token itself. Remove the word Bearer and any quotes that came along from a header or JSON response.

  4. Check the alg field in the header. A token signed with a different algorithm from the one your server expects will fail verification.

  5. Look at aud and iss when a token works on one service but not another. They say who issued the token and who it was meant for.

Frequently Asked Questions

Answers to common questions about this tool.

Is it safe to paste a real JWT here?

The token is decoded by JavaScript inside this tab and is not sent to a server. Even so, a live token is a key to an account until it expires, so treat it with care and avoid pasting tokens for systems you do not own.

Does this verify the JWT signature?

No. This page decodes and explains the contents only. Checking the signature needs the secret or public key that signed it, and a decoded payload tells you nothing about whether it is genuine.

Why can anyone read my JWT payload?

The header and payload are only Base64URL encoded, which is a way of writing bytes as text, not a form of encryption. The signature protects against changes, not against reading. Use encrypted tokens (JWE) if the contents must stay private.

What does exp mean in a JWT?

exp is the expiry time, written as seconds since 1 January 1970 in UTC. After that moment the token must be rejected. This page shows it as a normal date and warns you when it has already passed.

Why does my token show an error?

A JWT needs three parts separated by dots, and the first two must decode to valid JSON. Extra spaces, a missing section or a cut-off copy are the usual causes. Copy the token again from the source and paste it without any surrounding text.

Are the keys and passwords made here truly random?

They come from the browser’s built-in secure random number generator, the same source used for encrypted connections. That is suitable for passwords, keys and tokens.

Does JWT Inspector send my secrets to a server?

No. Everything is worked out locally, and what you type or generate is neither uploaded nor logged. For real production keys, it is still wise to generate them on the machine where they will be used.

Is JWT Inspector free for commercial projects?

Yes. Use it for personal, work or client projects at no cost and without an account. What you generate belongs to you, and the site keeps no copy.

Can a hash be reversed to get the original text?

No. A hash is one-way. Short or common passwords can still be guessed by trying many candidates, which is why a long, random password matters more than the hash you pick.

Further reading

More Security & Crypto Tools

Other free tools for the same kind of job.

Browse all tools