Purpose
Inspect JWT headers and payload claims without claiming signature verification.
How it works
The first two JWT segments are Base64url JSON; a trusted key must verify the signature before alg, role, aud, or exp can be trusted.
Input
Enter text, numbers, a file, or a query target as required. Start with the page example to confirm the format, then replace it with your data.
Interpreting output
Confirm output format, units, and status, then compare with the input and target environment; successful formatting does not prove validity.
Limitations and privacy
This tool processes input locally in the browser and does not send it to the server.