How to use it
- 1
Paste a three-segment compact JWT/JWS.
- 2
Select an allowed clock skew when needed.
- 3
Review the header, payload, temporal claims, and security warnings.
What the tool can do
- Strict Base64URL, UTF-8, and JSON-object parsing for header and payload.
- Inspection of exp, nbf, and iat against the browser clock with configurable clock skew.
- Review of iss, sub, aud, and jti claims plus warnings for alg=none, missing alg, and an empty signature.
Common use cases
- Reviewing claims in a test access or ID token during development.
- Finding malformed Base64URL, JSON, or NumericDate values.
- Investigating why exp or nbf appears incorrect.
How it works inside
JWT input is capped at 64 KiB and JSON at depth 64 and 5,000 nodes; the token is not stored, logged, or sent over the network.
Decoded values are rendered as text/JSON and are not inserted through dynamic HTML markup.
Questions and answers
Does decoding verify a JWT signature?
No. Anyone can construct similar header and payload data. Authenticity requires signature verification with a trusted key, algorithm, and policy in the accepting system.
Does the tool upload the token or fetch JWKS?
No. Processing is local, and the tool uses no network requests, history, or persistent storage.
