JWT Inspector
Decode a JWT to read its header, claims, and expiry, in UTC and your time zone.
Your data stays in your browser
Advertisement
Token to inspect
Paste a JWT
Token
No resultPaste a JWT in Token to inspect, or a log line or header that holds one.
Advertisement
Example
Decoded without a key · times in UTC
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTQyIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlzcyI6InF1aWNrbWVsZC1kZW1vIiwiYXVkIjoib3JkZXJzLWFwaSIsImlhdCI6MTc5MDAwMDAwMCwiZXhwIjoxNzkwMDAzNjAwfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Output
alg HS256 · typ JWT iss quickmeld-demo · sub user-42 · aud orders-api iat 2026-09-21 14:13:20 UTC exp 2026-09-21 15:13:20 UTC
How it works
- Paste a token, a
Bearerheader, or a log line that holds one. The header and payload are decoded and shown as JSON, with the algorithm in plain words. - Registered and OpenID Connect claims, such as
iss,sub,aud,scope, andemail, are explained. Every other claim is listed as it is. - Issued, not-before, and expiry times are shown in UTC and in your time zone, with how long ago or how soon, and whether the token is valid now by this device's clock.
- Format problems are named, such as a missing part, bad base64url,
algnone, or times in milliseconds. Signatures are not verified, and the token never leaves your browser.