Client-Side DecoderZero Server Transmission

JWT Inspector

Ad

Google Cloud • AI & Developer Infrastructure

Learn More
Encoded Token
HEADER: Algorithm & Token Type
// Waiting for valid token...
PAYLOAD: Data Claims & Subject
// Waiting for valid token...
SIGNATURE
No signature available
EPOCH TIMELINES
Issued At: N/A
Status: N/A
Technical Guide & Specifications

Anatomy of JSON Web Tokens (RFC 7519) & Cryptographic Signing

JSON Web Tokens (JWT) are an open, industry-standard RFC 7519 method for representing claims securely between two parties. Tokens consist of three Base64URL-encoded segments separated by dots: Header, Payload, and Signature. DevCraft parses and formats all claims entirely in local memory without exposing secrets to third-party endpoints.

How It Works (In-Memory Execution)

  1. Base64URL Splitting: The token string is split into three discrete segments by delimiter dots (.).
  2. Padding & Encoding Correction: Base64URL characters (- and _) are converted into standard Base64 characters (+ and /) with requisite equals (=) padding.
  3. Claims Parsing & Timestamp Conversion: The payload JSON is deserialized into an object, and standard Unix epoch integers (iat, exp, nbf) are mapped to human-readable locale timestamps.
  4. Active Expiration Differential: The engine computes the difference between Date.now() and the expiration timestamp (exp * 1000) to render an active countdown badge.

Standard Registered JWT Claims (RFC 7519)

Parameter / TokenDescriptionExample
iss (Issuer)Identifies the principal that issued the JWT (e.g. https://auth.company.com)."iss": "https://accounts.google.com"
sub (Subject)Identifies the principal that is the subject of the JWT (e.g. user UUID)."sub": "usr_99812481"
aud (Audience)Identifies the recipients that the JWT is intended for (API client or URL)."aud": "https://api.domain.com"
exp (Expiration)Unix timestamp after which the token must not be accepted for processing."exp": 1790924000
iat (Issued At)Unix timestamp identifying the time at which the JWT was created."iat": 1790837600

Frequently Asked Questions

Q: Is it safe to paste production JWT tokens here?

Yes. Unlike standard online decoders that send tokens over HTTPS to a remote backend, DevCraft runs 100% in client-side JavaScript. No network packets are sent.

Q: What is the difference between HS256 and RS256/Ed25519?

HS256 is a symmetric algorithm using a single shared secret key. RS256 (RSA) and Ed25519 (EdDSA) are asymmetric algorithms using a private key for signing and a public key (JWKS) for verification.

Q: Can someone read the contents of an unencrypted JWT?

Yes. Standard JWTs (JWS) are signed, not encrypted. Anyone who has the token can decode the Base64URL string to view claims. Never store sensitive passwords or credit card numbers in a standard JWT.