D2D Utilities
▼

JWT Inspector & Verifier

SubtleCrypto Verifier

Inspect JSON Web Tokens, evaluate claims, track expiration validity, and verify HMAC signatures locally via Web Crypto Subtle without transmitting credentials.

Client-Side Cryptography: JWTs and secrets never leave your browser
HMAC Signature Verification
Decoded (Signature Unverified)
Active / Valid Exp
Header:
{
  "alg": "HS256",
  "typ": "JWT"
}
Payload Claims:
{
  "sub": "usr-9982",
  "name": "Alex Chen",
  "role": "admin",
  "iss": "auth.platform.io",
  "exp": 1999999999,
  "iat": 1680000000
}

Security & Verification Distinction

Decoding a token only extracts claims and does not prove authenticity. A token is only trustworthy once its signature is validated against the signing secret with standard Web Crypto.

How to inspect and verify JWT tokens

  1. 1Paste your encoded JWT token into the editor.
  2. 2Inspect decoded header and payload claims.
  3. 3Optionally provide your HMAC secret to mathematically verify the signature.

Frequently Asked Questions

Are secrets sent to a backend?

No. Cryptographic verification runs entirely via the browser Web Crypto Subtle API.