Decode JWT headers and payloads locally, inspect timestamps, and clearly mark the signature as unverified.
Paste your encoded JWT token. The inspector displays formatted JSON for the algorithm header, payload claims, and human-readable expiration dates.
Yes. All operations run 100% inside your local web browser runtime using client-side JavaScript. No text, tokens, code, or personal data are ever uploaded to an external server or cloud service.
Yes. You can install the packaged Manifest V3 Chrome Extension version from GitHub or save this standalone HTML page locally to use without an internet connection.
Yes, all tools are 100% free and licensed under the permissive MIT license. If this tool helped you solve an annoyance, you can support development at ko-fi.com/jju1s.