QuickMeld

JWT Inspector

Decode a JWT to read its header, claims, and expiry, in UTC and your time zone.

Your data stays in your browser

Advertisement

Token to inspect

Paste a JWT

Token

No result

Paste a JWT in Token to inspect, or a log line or header that holds one.

Advertisement

Example

Decoded without a key · times in UTC

Input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTQyIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlzcyI6InF1aWNrbWVsZC1kZW1vIiwiYXVkIjoib3JkZXJzLWFwaSIsImlhdCI6MTc5MDAwMDAwMCwiZXhwIjoxNzkwMDAzNjAwfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Output

alg HS256 · typ JWT
iss quickmeld-demo · sub user-42 · aud orders-api
iat 2026-09-21 14:13:20 UTC
exp 2026-09-21 15:13:20 UTC

How it works

  • Paste a token, a Bearer header, or a log line that holds one. The header and payload are decoded and shown as JSON, with the algorithm in plain words.
  • Registered and OpenID Connect claims, such as iss, sub, aud, scope, and email, are explained. Every other claim is listed as it is.
  • Issued, not-before, and expiry times are shown in UTC and in your time zone, with how long ago or how soon, and whether the token is valid now by this device's clock.
  • Format problems are named, such as a missing part, bad base64url, alg none, or times in milliseconds. Signatures are not verified, and the token never leaves your browser.