Decode, inspect, and debug JSON Web Tokens (JWT) to analyze Header algorithms, Payload claims, expiration timestamps (exp), and signature structure without sharing secrets.
Decoding a JWT inspects claims in browser memory, but does NOT verify signature authenticity against a secret key or public RSA key. Always perform server-side signature verification before trusting token claims.
{
"alg": "HS256",
"typ": "JWT"
}| Claim | Value / Timestamp | Description | Action |
|---|---|---|---|
| sub | 1234567890 | Subject (user ID or principal) | |
| name | Alex Dev | Custom Claim | |
| role | admin | Custom Claim | |
| iat | 1/18/2018, 7:00:22 AM (Thu, 18 Jan 2018 01:30:22 GMT) | Issued At (creation timestamp) | |
| exp | 9/21/2030, 10:07:02 PM (Sat, 21 Sep 2030 16:37:02 GMT) | Expiration Time (token validity ceiling) |
{
"sub": "1234567890",
"name": "Alex Dev",
"role": "admin",
"iat": 1516239022,
"exp": 1916239022
}sub), role permissions, issued-at timestamps (iat), and expiration dates (exp)—without sending sensitive tokens to remote servers. The JSON Web Token (JWT) Inspector & Debugger parses and displays token headers and claims in real time with human-readable timestamp conversions and expiration status alerts.A standard JWT is composed of three distinct sections separated by dots (.):
$$\text{JWT} = \underbrace{\text{Header}}_{\text{Base64URL}} \, . \, \underbrace{\text{Payload}}_{\text{Base64URL}} \, . \, \underbrace{\text{Signature}}_{\text{HMAC / RSA}}$$
"alg": "HS256" or "RS256") and token type ("typ": "JWT").sub (Subject): The unique user ID or account identifier.iat (Issued At): Unix epoch timestamp when the token was generated.exp (Expiration Time): Unix epoch timestamp when the token expires.nbf (Not Before): Timestamp before which the token must not be accepted."roles": ["admin"]), email addresses, and tenant identifiers.Our inspector automatically translates numeric Unix epoch timestamps (exp: 1772345678) into formatted local dates (e.g. August 29, 2026, 10:15 AM), flagging expired tokens in red.
eyJhbGci...) into the editor workspace.alg) and token type.iat, exp, and nbf into human-readable local dates.Scenario: Inspecting user role claims and expiration time on an OAuth access token.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFsZXggQ2hlbiIsImFkbWluIjp0cnVlLCJleHAiOjE3NzIzNDU2Nzh9.signature
Header: {"alg": "HS256", "typ": "JWT"}
Payload: {"sub": "1234567890", "name": "Alex Chen", "admin": true, "exp": 1772345678}
Status: Token Active ✅Decodes claims and translates expiration timestamp into readable date.
Scenario: Debugging why an API request returned a 401 Unauthorized error.
JWT with exp set to a past timestamp
Status: EXPIRED ❌ (Expired on May 12, 2024)
Alerts the developer that the token has expired.