JWT Inspector
Decode a JSON Web Token, verify its signature, and check it the way your API should — plus inspect a JWKS or OpenID Connect configuration for risky settings.
How to use
- Paste the token (a leading "Bearer " is fine).
- Read the claims, expiry and warnings.
- Add the secret or public key to verify, then set your API’s rules for a clear accept / reject.
- Optional: paste your provider’s JWKS or openid-configuration to check its keys and settings.
Inspect a JWKS or OpenID configuration
Open your provider’s /.well-known/openid-configuration or its jwks_uri in another tab and paste the JSON here.
Common questions
Is it safe to paste a JWT into an online decoder?
Only if the page cannot send it anywhere. A valid token works like a password for as long as it lives. This page is locked by your browser so it cannot make connections, which you can test with the “Test the lock” button.
How do I verify a JWT signature?
Paste the token, then add the shared secret (HS256) or the public key (RS256, ES256, EdDSA) as PEM or JWK. For providers such as Entra ID, Okta or Auth0, paste their JWKS and choose “Use these keys to verify”.
Why should an API reject a token with a valid signature?
A signature only proves who issued the token. The API must also check the issuer, the audience (that the token was meant for this API), the algorithm and the expiry — “Validate like your API” runs those checks.
Known limitations
- Cannot fetch keys from a JWKS URL (the page has no network access) — paste the JSON instead.
- Encrypted tokens (JWE) cannot be read without the decryption key.
- The validation mirrors common API checks; your framework may add others (scopes, custom claims, token binding).
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- RFC 7519 — JSON Web Token (opens in a new tab)
- RFC 7515 — JSON Web Signature (opens in a new tab)
- RFC 7517 — JSON Web Key (JWKS) (opens in a new tab)
- RFC 7638 — JWK thumbprint (opens in a new tab)
- OpenID Connect Discovery 1.0 (opens in a new tab)
- RFC 9700 — OAuth 2.0 Security Best Current Practice (opens in a new tab)
- RFC 8725 — JWT Best Current Practices (opens in a new tab)
- RFC 9068 — JWT access tokens (typ at+jwt) (opens in a new tab)
- OpenID Connect Core 1.0 (opens in a new tab)