Herramienta browser-only
Decodificador JWT
Inspecciona claims para depuracion, recordando que decodificar no es verificar.
Herramienta browser-only
Inspecciona claims para depuracion, recordando que decodificar no es verificar.
Advertencia: decodificar no significa verificar. No pegues tokens de produccion si no confias en este entorno local.
La firma no se verifica en esta herramienta.
JWT decoding runs locally in your browser. The token is not uploaded by this static page.
No. It decodes header and payload only. Verification needs trusted keys and issuer rules.
Avoid it. Tokens can grant access and may also be stored in browser history or screenshots.
The tool decodes the Base64URL header and payload. It shows the signature segment but does not validate it.
Not without signature, issuer, audience, expiry, and policy validation.
JWT inspection is useful for debugging, but the page must clearly warn about risks and avoid uploading data.