← All tools

JWT Claims Inspector

Decode JWT claims and verify nine HMAC, RSA, or ECDSA signatures locally without uploading your token or key.

Decode and verify locally. Your token and key stay in this browser.

Signing algorithm

Supported algorithms: HS256, HS384, HS512, RS256, RS384, RS512, ES256, ES384, ES512

Secret encoding
Claim timezone

A valid signature does not prove expiry, issuer, audience, authorization, or safety.

How to use this tool

Inspect a local or disposable test token to compare issuer, audience, and expiration claims with an integration contract.

When not to use it

Do not paste a production bearer token or treat decoded claims as verified authorization.

Read the guide →