Decode JWT header and payload locally, inspect UTC timestamps and expiry warnings. No API calls. Signature verification is not performed.
Use this free browser tool for a focused check of your text. Start with the fictional sample to understand the output, then analyze your own input and review the stated limits.
How to use
Paste a three-part compact JWT and choose Analyze. Header and payload appear as formatted JSON with UTC times for exp, nbf and iat. The sample is deliberately unsigned and contains only fictional data.

How it works
Decoding reveals readable claims; it does not establish identity, issuer authenticity or permission. This inspector never verifies a signature and does not fetch keys or contact an issuer. The server must validate algorithms, issuer, audience, signature and application policy.
Limits and review
The tool accepts UTF-8 JSON objects with canonical unpadded Base64url segments. Encrypted five-part JWE tokens, broken JSON, malformed segments and unsupported timestamps produce errors. Date warnings use your device clock and no clock-skew allowance.
Example and results
A token with exp equal to the current time is reported expired. A future nbf is reported not yet active. Both statements describe the decoded claim and local clock only; a fabricated token can contain any date.
Practical guidance
Inspect a development token to locate a wrong claim name or timestamp. Do not use the output to decide whether someone should access an account. Copy sends the result to your clipboard only when you click it.
Frequently asked questions
Does it require an API?
No. This tool processes input locally in JavaScript without an external service.
Is input saved?
The tool keeps no input history or server copy. Copying places the result in your clipboard.
What happens when input changes?
The old result clears. Analyze again to generate output for the current input.
Is the result a final decision?
The tool accepts UTF-8 JSON objects with canonical unpadded Base64url segments. Encrypted five-part JWE tokens, broken JSON, malformed segments and unsupported timestamps produce errors. Date warnings use your device clock and no clock-skew allowance.