D2D Utilities
▼

JWT Inspector & Verifier

SubtleCrypto Verifier

Inspect JSON Web Tokens, evaluate claims, track expiration validity, and verify HMAC signatures locally via Web Crypto Subtle without transmitting credentials.

Client-Side Cryptography: JWTs and secrets never leave your browser
HMAC Signature Verification
Decoded (Signature Unverified)
Active / Valid Exp
Header:
{
  "alg": "HS256",
  "typ": "JWT"
}
Payload Claims:
{
  "sub": "usr-9982",
  "name": "Alex Chen",
  "role": "admin",
  "iss": "auth.platform.io",
  "exp": 1999999999,
  "iat": 1680000000
}

Security & Verification Distinction

Decoding a token only extracts claims and does not prove authenticity. A token is only trustworthy once its signature is validated against the signing secret with standard Web Crypto.

Comment inspecter un jeton JWT

  1. 1Collez votre jeton JWT.
  2. 2Vérifiez la signature avec votre clé secrète.

Frequently Asked Questions

La clé secrète est-elle protégée ?

Oui, elle ne quitte jamais votre navigateur.