JWT & SSL Certificate Inspector – Offline Token & X.509 Decoder
{}
{}
What is a JSON Web Token (JWT)?
A JSON Web Token (JWT) is an open, industry-standard RFC 7519 method for securely transmitting information between parties as a compact JSON object. JWTs are digitally signed using either a secret key (HMAC SHA-256) or a public/private key pair (RSA / ECDSA).
Anatomy of a JWT Token
- Header (Red): Contains metadata about the token, typically the signing algorithm (
alg: "HS256") and token type (typ: "JWT"). - Payload (Purple): Contains the claims. Common standard claims include
sub(subject identifier),iss(issuer),aud(audience),iat(issued-at timestamp), andexp(expiration timestamp). - Signature (Blue): Produced by hashing the encoded header and payload together with your private secret:
HMACSHA256(base64UrlEncode(header) + "." + base64UrlEncode(payload), secret).
Why Inspect X.509 SSL Certificates Offline?
Production certificates expire every 90 days under modern CA standards (Let's Encrypt, ZeroSSL, Google Trust Services). Manually uploading company certificates to untrusted third-party web tools risks exposing sensitive intermediate authority chains and internal domain topologies. Our offline X.509 inspector extracts validity bounds, Subject Alternative Name (SAN) coverage, and cryptographic fingerprints without transmitting a single byte over the wire.
Frequently asked questions
Is it safe to paste production JWTs or SSL certificates here?
Yes, absolutely. Decoding occurs entirely within your browser's JavaScript engine using window.atob and window.crypto.subtle. No network requests are made.
How does expiration calculation work?
The tool parses the exp claim (epoch timestamp in seconds) from the payload, compares it with your device clock (Date.now()), and displays the exact time remaining or when it expired.
Can I verify RS256 or asymmetric tokens?
This tool currently provides signature calculation for HS256 (HMAC SHA-256). For asymmetric algorithms (RS256, ES256), the header and payload claims are fully decoded and validated for expiration.
What are Subject Alternative Names (SANs)?
SANs specify additional hostnames (e.g. *.example.com, api.example.com, staging.example.com) protected by a single SSL/TLS certificate.