A worked example, rendered from real sample data. Sign in to run the tool on your own input.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImFwaS1zaWduaW5nLTIwMjYifQ.eyJpc3MiOiJodHRwczovL2F1dGguYWNtZS5leGFtcGxlIiwic3ViIjoic3ZjX3JlcG9ydGluZyIsImF1ZCI6Imh0dHBzOi8vYXBpLmFjbWUuZXhhbXBsZSIsImV4cCI6MTgyMDAwMDAwMCwiaWF0IjoxNzg5MDAwMDAwLCJuYmYiOjE3ODkwMDAwMDAsImp0aSI6IjNmOWMyYTExIiwic2NvcGUiOiJyZWFkOnJlcG9ydHMifQ.BtWXBpw8N4mv8ewK4IZt7-6u9rpfAM7QMw6fdyIDDrY═══ Token inspected ═══
Verdict: a strict verifier would ACCEPT this token
Algorithm: HS256
Size: 357 bytes (header 70c · payload 242c · signature 43c)
─── Token ───
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImFwaS1zaWduaW5nLTIwMjYifQ.eyJpc3MiOiJodHRwczovL2F1dGguYWNtZS5leGFtcGxlIiwic3ViIjoic3ZjX3JlcG9ydGluZyIsImF1ZCI6Imh0dHBzOi8vYXBpLmFjbWUuZXhhbXBsZSIsImV4cCI6MTgyMDAwMDAwMCwiaWF0IjoxNzg5MDAwMDAwLCJuYmYiOjE3ODkwMDAwMDAsImp0aSI6IjNmOWMyYTExIiwic2NvcGUiOiJyZWFkOnJlcG9ydHMifQ.BtWXBpw8N4mv8ewK4IZt7-6u9rpfAM7QMw6fdyIDDrY
─── Header ───
{
"alg": "HS256",
"typ": "JWT",
"kid": "api-signing-2026"
}
─── Payload ───
{
"iss": "https://auth.acme.example",
"sub": "svc_reporting",
"aud": "https://api.acme.example",
"exp": 1820000000,
"iat": 1789000000,
"nbf": 1789000000,
"jti": "3f9c2a11",
"scope": "read:reports"
}
═══ What a verifier would say ═══
✓ alg is HS256. Pin this value in your verifier; never take the algorithm from the token itself.
ℹ Signature not checked: supply the HMAC secret to have it verified here.
✓ exp is 348 days away (2027-09-03T19:33:20Z).
═══ Timeline ═══
now: 2026-09-20T12:07:29Z
iat: 2026-09-10T00:26:40Z (10 days ago)
nbf: 2026-09-10T00:26:40Z (10 days ago)
exp: 2027-09-03T19:33:20Z (in 348 days)
Build or take apart a JWT and see exactly which checks a verifier would fail it on. Part of the DevTools Surf developer suite. Browse more tools in the Security / Crypto collection.