Developer Security Utility
JWT Decoder & Claim Inspector
Inspect JSON Web Token payload claims, live expiration countdowns, and verify signatures securely in your browser.
Private by default. Processing happens in your browser.
- Add your inputChoose a file, paste content, or enter details.
- Choose settingsReview the useful defaults, then adjust if needed.
- Save the resultCopy or download the finished output.
Encoded JSON Web Token
Paste your JWT to inspect claims, validity, and signatures locally
Token Active & Valid
Expires in 1h 59mExpires: Thu, 01 Oct 2026 08:11:27 GMT
Decoded Payload Claims
Identifies the principal that issued the JWT.
Identifies the principal that is the subject of the JWT (user ID).
Identifies the recipients that the JWT is intended for.
[ "https://api.kinetiqit.com/v1", "https://app.kinetiqit.com" ]
Timestamp at which the JWT was issued.
Timestamp before which the JWT MUST NOT be accepted.
Timestamp after which the JWT MUST NOT be accepted for processing.
Unique identifier for the token, used to prevent replay attacks.
User's email address.
Whether the user's email has been verified.
User's full name.
Assigned access control roles.
[ "admin", "architect" ]
Granted OAuth2 scopes or permissions.
JWT Header
{
"alg": "HS256",
"typ": "JWT"
}Verify Signature
🔒 Verification runs entirely in your browser using the native Web Crypto API. Your secret keys are never transmitted.
Zero Server Transmission
JWTs and secret keys are decoded client-side using JavaScript. No tokens or authentication payloads ever leave your browser.
Live Expiration Inspector
Instantly checks standard timestamps (`exp`, `iat`, `nbf`) with relative time countdowns and lifespan elapsed percentage bar.
HMAC Signature Verifier
Verify HS256/384/512 signatures with your secret key directly in the browser using the W3C Web Cryptography standard API.
Fast, transparent JWT debugging for modern authentication
Inspect OAuth2, OpenID Connect, Firebase, Supabase, and custom auth tokens with complete privacy.
3-Part JWT Decomposition
Automatically splits and visualizes the Header (Rose), Payload (Indigo), and Signature (Sky) segments.
Live Expiration & Lifespan
Calculates real-time token validity, remaining time countdowns, and visual lifecycle progress bars.
WebCrypto Signature Verification
Verify HS256/384/512 HMAC signatures using your secret key directly in the browser with native Web Crypto APIs.
RFC-7519 Claim Explanations
Translates standard claims (iss, sub, aud, exp, nbf, iat, jti) into plain human-readable explanations and local times.
1-Click Developer Exports
Copy formatted JSON payloads, clean headers, and cURL `Authorization: Bearer <token>` strings instantly.
100% In-Browser Privacy
Your tokens, secrets, and authorization claims are decoded locally in JavaScript. No data ever leaves your device.
Frequently asked questions
- What is a JSON Web Token (JWT)?
- A JSON Web Token (RFC 7519) is a compact, URL-safe means of representing claims to be transferred between two parties. It consists of three parts separated by dots: Header, Payload (claims), and Signature.
- Is it safe to paste private tokens and secrets here?
- Yes. This tool is 100% client-side. All Base64Url decoding, JSON parsing, and HMAC signature verification execute in your browser's local sandbox without making any HTTP requests or logging any tokens.
- How does the live expiration countdown work?
- The tool extracts the `exp` (expiration time) and `iat` (issued at) numeric epoch timestamps from the token payload and compares them against your system's current time, calculating the exact remaining duration and percentage of lifespan elapsed.
- Which signature algorithms are supported for verification?
- Symmetric HMAC algorithms (HS256, HS384, HS512) are verified locally using your secret key via the W3C Web Cryptography API. Asymmetric tokens (RS256, ES256) will be decoded for claim inspection.
- Can I inspect custom claims like roles and permissions?
- Yes! The claims inspector parses all custom payload attributes, including nested JSON objects, boolean flags, arrays of permissions, and user profile metadata.
Building authentication or microservices?
KinetiqIT engineers secure single-sign-on (SSO), OAuth2 identity systems, and high-performance backend APIs.
Talk to our engineers