JWT content verification
JWT check header, payload, expiration, and issuance time. No tokens are stored or transmitted; signature verification is not performed.
Input is not saved or sent. Sharing includes only a summary.
Result
Results appear here after execution.
View the original report·copy directly
Share result
Share the tool link and result text together. No URL is included in the result. Check the below content and then share it.
Usage examples and processing criteria
Decoding a token where alg is none and sub is sample-user shows separate header and payload JSON. exp=1704153600 is UTC 2024-01-02 00:00:00. If the device clock is after this time, it shows “expiration time elapsed”, but it does not confirm the validity of the signature, issuer, or permissions.
Frequently Asked Questions
Can you determine if a token is valid?
No. Only performs Base64url decoding. No signature, algorithm allowed list, issuer, or target verification, so authentication success or security cannot be determined. Alerts are given for alg=none or empty signatures.
What formats are supported?
Header with points. Supports header, payload, and signature 3 parts of JWT JSON objects. Up to 100,000 characters; indicates encrypted 5 parts JWE, duplicate JSON keys, and incorrect UTF-8 errors.
How are large numbers and time displayed?
exp·nbf·iat are interpreted as Unix seconds, showing both UTC and device local time. If the number is not a number or outside a date range, an alert is displayed. Large numbers from the original JSON are preserved, but date conversion uses the browser’s millisecond precision. The results are based on the execution time and do not update automatically.
Do you save or share tokens?
Tokens are not added to browser storage, address, and analysis events. Result sharing includes only unverified summaries. For copying and file saving, the decoded content is included, so verify the saved and shared location you choose.
Calculation criteria and reference materials
- RFC 7519 — JSON Web Token
JWT structure, NumericDate, and registered time claim. This tool does not implement verification procedures.
- RFC 4648 — Base encoding
Difference between Base64 letters and Base64url
Verification of calculation criteria: · Calculation·verification principles · Report errors