JWT Inspector

Decode a JSON Web Token, verify its signature, and check it the way your API should — plus inspect a JWKS or OpenID Connect configuration for risky settings.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Paste the token (a leading "Bearer " is fine).
  2. Read the claims, expiry and warnings.
  3. Add the secret or public key to verify, then set your API’s rules for a clear accept / reject.
  4. Optional: paste your provider’s JWKS or openid-configuration to check its keys and settings.
Inspect a JWKS or OpenID configuration

Open your provider’s /.well-known/openid-configuration or its jwks_uri in another tab and paste the JSON here.

Common questions

Is it safe to paste a JWT into an online decoder?

Only if the page cannot send it anywhere. A valid token works like a password for as long as it lives. This page is locked by your browser so it cannot make connections, which you can test with the “Test the lock” button.

How do I verify a JWT signature?

Paste the token, then add the shared secret (HS256) or the public key (RS256, ES256, EdDSA) as PEM or JWK. For providers such as Entra ID, Okta or Auth0, paste their JWKS and choose “Use these keys to verify”.

Why should an API reject a token with a valid signature?

A signature only proves who issued the token. The API must also check the issuer, the audience (that the token was meant for this API), the algorithm and the expiry — “Validate like your API” runs those checks.

Known limitations

  • Cannot fetch keys from a JWKS URL (the page has no network access) — paste the JSON instead.
  • Encrypted tokens (JWE) cannot be read without the decryption key.
  • The validation mirrors common API checks; your framework may add others (scopes, custom claims, token binding).
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07