Token inspection

JWT & Tokens

Separate and inspect a JSON Web Token’s encoded parts without sending it anywhere.

Decoding is not verification

Anyone can modify a JWT’s visible contents. Authenticity requires cryptographic signature verification using the correct trusted key and expected algorithm.

Header

Algorithm & type

Waiting for a token…
Payload

Claims & data

Waiting for a token…
Signature

Encoded signature

Waiting for a token…