Yoonadev

Data

JWT Analyzer & Generator

Analyze or sign a JWT

Read JWT claims, create signed test tokens or verify HMAC signatures in your browser.

A JWT often appears after login: an app sends this token with API requests, and the server checks its signature. A long eyJ… string with three dot-separated parts may be a JWT.

  1. Login succeeds
  2. Server puts user ID and role in the Payload and signs with its Secret
  3. App sends the JWT with an API request
  4. Server verifies the signature: unchanged token proceeds; changed token is rejected

Try an example

Task

No Secret is needed to read the Header and Payload: they are Base64URL text, not encrypted. Reading them does not establish trust. This view does not verify the Signature.

Input is processed in your browser.

Usage guideWhen to use · How to use · Understand results

When to use this tool

Read JWT claims, create signed test tokens or verify HMAC signatures in your browser.

How to use it

  1. After login, a server may issue a JWT and the app sends it with API calls. Decode / Inspect reads its fields without a Secret. Generate signs a synthetic test token with a Secret. Verify signature uses the same Secret to check for changes; try changing one character of the Secret.

Reading the result

Header describes format and algorithm; Payload contains claims; Signature allows a server to check changes. Reading a Payload is not verification. A matching signature alone does not validate identity, exp, nbf or service policy. Do not put passwords or sensitive data in the readable Payload.

Find a tool

↑ ↓ to select · Enter to open · Esc to close