JWT Debugger
Decode, verify, build, and security-audit JSON Web Tokens right in your browser. No data sent to any server. Full expiry visualization, HMAC signature verification, JWT builder with presets — plus a security scanner that catches alg:none, SSRF risks, missing claims, and more.
About JWT Debugger
JSON Web Tokens (JWT) are an open standard (RFC 7519) for securely transmitting information between parties as a JSON object. This tool lets you decode, verify, and build JWTs entirely in your browser — your tokens never leave your device.
Four Modes
- Decode: Instantly parse any JWT to inspect header, payload, and expiry — with human-readable timestamps for iat, nbf, and exp claims.
- Verify: Validate HMAC signatures (HS256/384/512) against a secret key using the Web Crypto API. Confirms the token is authentic and unmodified.
- Build: Create signed JWTs with your own claims, expiration, and secret. Preset payloads for common use cases (user sessions, service accounts, OTP).
- Security: Run a full security audit — detects alg:none, weak algorithms, SSRF risks (jku/x5u), missing claims, expired tokens, sensitive data in payload, and privilege escalation indicators. Traffic-light scoring (🟢 PASS / 🟡 WARN / 🔴 CRITICAL).
Privacy
All operations use the browser's built-in Web Crypto API via the jose library.
Nothing is sent to any server. Safe to use with real tokens during debugging.
JWT vs jwt.io
jwt.io is operated by Auth0/Okta. If you'd rather keep your tokens off third-party servers, this tool runs entirely locally. It supports the same core debugging workflow with the added benefit of expiry visualization and a built-in JWT generator.