ZERO-TRUST JWT DIAGNOSTICS
Inspect tokens.
Keep them yours.
Decode, lint, verify, and re-sign JSON Web Tokens entirely in your browser. No uploads. No accounts. No trackers.
CSP isolation active · checking local service worker
Token inspection
Payload
Signature
Security linter
Token time
Verify or sign locally
For HMAC, paste the shared secret. For RSA/ECDSA verification paste a public PEM; for signing paste a private PKCS#8 PEM. Key material remains in memory only.
Local token editor
Edit only tokens you are authorized to use in local or mock environments.
A small tool for everyday auth debugging
JWT payloads are Base64URL encoded—not secret. easyjwt turns a pasted token into an immediate security and time diagnostic without routing credentials through a third-party decoder.