🔐 Encoded Token

Header Payload Signature
⚪ Paste a JWT token above to inspect expiration. 0 bytes

Header: Algorithm & Token Type

alg: HS256

Payload: Data Claims

0 claims

Signature Verification (Web Crypto API)

⚪ Enter Secret Key

🔒 Why You Should Never Paste Real Tokens into jwt.io

JSON Web Tokens (JWT) are commonly used for Bearer authentication, session management, and OAuth / OpenID Connect ID tokens. They frequently carry customer user IDs, email addresses, IAM permission roles, and cryptographic hashes.

Pasting production tokens into public third-party web tools risks accidental credential leaks and breaches strict enterprise DLP / SOC2 data handling policies. LigTools JWT Inspector runs 100% locally in your browser memory using the browser's native crypto.subtle Web Crypto API. No data packets ever leave your machine.

Frequently Asked Questions

Yes. This tool runs 100% locally in your browser using the native Web Crypto API. Unlike online decoders, your tokens, headers, payloads, and signing keys are never transmitted over the internet or logged to any remote server.

The tool supports HMAC SHA-256 (HS256), HMAC SHA-384 (HS384), and HMAC SHA-512 (HS512) with symmetric secret keys, as well as RSA SHA-256 (RS256) with public keys in PEM format, all computed client-side.

The inspector parses the standard 'exp' (expiration time) and 'nbf' (not before) claims in UNIX epoch seconds, compares them with your system's current time, and displays a real-time human-readable countdown badge.