Data
JWT Analyzer & Generator
Analyze or sign a JWT
Read JWT claims, create signed test tokens or verify HMAC signatures in your browser.
A JWT often appears after login: an app sends this token with API requests, and the server checks its signature. A long eyJ… string with three dot-separated parts may be a JWT.
- Login succeeds
- Server puts user ID and role in the Payload and signs with its Secret
- App sends the JWT with an API request
- Server verifies the signature: unchanged token proceeds; changed token is rejected
Try an example
Result
BeforeAfter
| Key | Value |
|---|
Usage guideWhen to use · How to use · Understand results
When to use this tool
Read JWT claims, create signed test tokens or verify HMAC signatures in your browser.
How to use it
- After login, a server may issue a JWT and the app sends it with API calls. Decode / Inspect reads its fields without a Secret. Generate signs a synthetic test token with a Secret. Verify signature uses the same Secret to check for changes; try changing one character of the Secret.
Reading the result
Header describes format and algorithm; Payload contains claims; Signature allows a server to check changes. Reading a Payload is not verification. A matching signature alone does not validate identity, exp, nbf or service policy. Do not put passwords or sensitive data in the readable Payload.