Skip to main content
All tools

Developer Security Utility

JWT Decoder & Claim Inspector

Inspect JSON Web Token payload claims, live expiration countdowns, and verify signatures securely in your browser.

Private by default. Processing happens in your browser.

  1. Add your inputChoose a file, paste content, or enter details.
  2. Choose settingsReview the useful defaults, then adjust if needed.
  3. Save the resultCopy or download the finished output.

Encoded JSON Web Token

Paste your JWT to inspect claims, validity, and signatures locally

Segments:Header (36 chars)Payload (512 chars)Signature (43 chars)
Load Preset:
100% In-Browser Execution

Token Active & Valid

Expires in 1h 59m

Expires: Thu, 01 Oct 2026 08:11:27 GMT

Token Lifespan20% Elapsed

Decoded Payload Claims

issIssuer

Identifies the principal that issued the JWT.

https://auth.kinetiqit.com/
subSubject

Identifies the principal that is the subject of the JWT (user ID).

usr_99a82b4c10ef
audAudience

Identifies the recipients that the JWT is intended for.

[
  "https://api.kinetiqit.com/v1",
  "https://app.kinetiqit.com"
]
iatIssued At

Timestamp at which the JWT was issued.

1790833287(10/1/2026, 5:41:27 AM)
nbfNot Before

Timestamp before which the JWT MUST NOT be accepted.

1790833287(10/1/2026, 5:41:27 AM)
expExpiration Time

Timestamp after which the JWT MUST NOT be accepted for processing.

1790842287(10/1/2026, 8:11:27 AM)
jtiJWT ID

Unique identifier for the token, used to prevent replay attacks.

jwt_847291038472
emailEmail Address

User's email address.

alexander.wright@kinetiqit.com
email_verifiedEmail Verified

Whether the user's email has been verified.

true
nameFull Name

User's full name.

Alexander Wright
rolesRoles

Assigned access control roles.

[
  "admin",
  "architect"
]
scopeScopes

Granted OAuth2 scopes or permissions.

openid profile email read:projects write:projects

JWT Header

HS256
Algorithm (alg):HS256
Type (typ):JWT
{
  "alg": "HS256",
  "typ": "JWT"
}

Verify Signature

WebCrypto

🔒 Verification runs entirely in your browser using the native Web Crypto API. Your secret keys are never transmitted.

cURL Auth Header
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpX...
100% In-Browser

Zero Server Transmission

JWTs and secret keys are decoded client-side using JavaScript. No tokens or authentication payloads ever leave your browser.

Private & secure sandbox
Real-Time

Live Expiration Inspector

Instantly checks standard timestamps (`exp`, `iat`, `nbf`) with relative time countdowns and lifespan elapsed percentage bar.

UTC & local time translations
WebCrypto

HMAC Signature Verifier

Verify HS256/384/512 signatures with your secret key directly in the browser using the W3C Web Cryptography standard API.

Tamper detection & verification
Need a hand?

Start with your input above. The preview and available download or copy actions will update as you work.

Browse every browser tool

Fast, transparent JWT debugging for modern authentication

Inspect OAuth2, OpenID Connect, Firebase, Supabase, and custom auth tokens with complete privacy.

3-Part JWT Decomposition

Automatically splits and visualizes the Header (Rose), Payload (Indigo), and Signature (Sky) segments.

Live Expiration & Lifespan

Calculates real-time token validity, remaining time countdowns, and visual lifecycle progress bars.

WebCrypto Signature Verification

Verify HS256/384/512 HMAC signatures using your secret key directly in the browser with native Web Crypto APIs.

RFC-7519 Claim Explanations

Translates standard claims (iss, sub, aud, exp, nbf, iat, jti) into plain human-readable explanations and local times.

1-Click Developer Exports

Copy formatted JSON payloads, clean headers, and cURL `Authorization: Bearer <token>` strings instantly.

100% In-Browser Privacy

Your tokens, secrets, and authorization claims are decoded locally in JavaScript. No data ever leaves your device.

Frequently asked questions

What is a JSON Web Token (JWT)?
A JSON Web Token (RFC 7519) is a compact, URL-safe means of representing claims to be transferred between two parties. It consists of three parts separated by dots: Header, Payload (claims), and Signature.
Is it safe to paste private tokens and secrets here?
Yes. This tool is 100% client-side. All Base64Url decoding, JSON parsing, and HMAC signature verification execute in your browser's local sandbox without making any HTTP requests or logging any tokens.
How does the live expiration countdown work?
The tool extracts the `exp` (expiration time) and `iat` (issued at) numeric epoch timestamps from the token payload and compares them against your system's current time, calculating the exact remaining duration and percentage of lifespan elapsed.
Which signature algorithms are supported for verification?
Symmetric HMAC algorithms (HS256, HS384, HS512) are verified locally using your secret key via the W3C Web Cryptography API. Asymmetric tokens (RS256, ES256) will be decoded for claim inspection.
Can I inspect custom claims like roles and permissions?
Yes! The claims inspector parses all custom payload attributes, including nested JSON objects, boolean flags, arrays of permissions, and user profile metadata.

Building authentication or microservices?

KinetiqIT engineers secure single-sign-on (SSO), OAuth2 identity systems, and high-performance backend APIs.

Talk to our engineers