For security reviewers and pentest learners checking how an application issues tokens. You get the decoded header and payload plus an expiry check, so you can spot risky settings such as a weak alg, a missing exp or sensitive data in claims.
Take an online exam and add a verified certificate to your public profile that anyone can check.
You enter
The sample HS256 token loaded on the page
The tool shows
Header {"alg":"HS256","typ":"JWT"}; payload {"sub":"1234567890","name":"CareerByteCode","iat":1516239022}; status: decoded, signature NOT verified (no exp claim, so no expiry shown)
Look at the alg (reject none, and watch for unexpected algorithm switches), confirm exp is present and short-lived, and make sure the payload holds no secrets, since anyone can decode it.
No. Decoding only reads the Base64url parts. Validity needs a signature check with the right key on the server; this inspector clearly marks the signature as not verified.
A token with no expiry stays usable until the key is rotated, so a leaked token keeps working. The inspector shows the expiry time when exp exists and flags expired tokens.
Yes. It is free, needs no sign-up and runs entirely in your browser, so what you type is not uploaded. You only sign in if you want to email a result to yourself or save it to your CareerByteCode profile.