Home›Freelancer tools›JWT & SSL Inspector

JWT & SSL Certificate Inspector – Offline Token & X.509 Decoder

Decode JSON Web Tokens (JWT) and inspect X.509 SSL certificates offline in your browser. Verify expiration, signatures, SANs, and SHA-256 fingerprints with 100% privacy.

Header (Algorithm & Token Type) JSON
{}
Payload (Data Claims & Timestamps) JSON
{}
Signature Verification (HMAC SHA-256) Verified in Browser via Web Crypto
-
100% Client-Side Privacy: Tokens, cryptographic secrets, and SSL certificates are decoded and verified entirely in your browser using the Web Crypto API. Zero data is ever sent to any remote server.

What is a JSON Web Token (JWT)?

A JSON Web Token (JWT) is an open, industry-standard RFC 7519 method for securely transmitting information between parties as a compact JSON object. JWTs are digitally signed using either a secret key (HMAC SHA-256) or a public/private key pair (RSA / ECDSA).

Anatomy of a JWT Token

Why Inspect X.509 SSL Certificates Offline?

Production certificates expire every 90 days under modern CA standards (Let's Encrypt, ZeroSSL, Google Trust Services). Manually uploading company certificates to untrusted third-party web tools risks exposing sensitive intermediate authority chains and internal domain topologies. Our offline X.509 inspector extracts validity bounds, Subject Alternative Name (SAN) coverage, and cryptographic fingerprints without transmitting a single byte over the wire.

Frequently asked questions

Is it safe to paste production JWTs or SSL certificates here?

Yes, absolutely. Decoding occurs entirely within your browser's JavaScript engine using window.atob and window.crypto.subtle. No network requests are made.

How does expiration calculation work?

The tool parses the exp claim (epoch timestamp in seconds) from the payload, compares it with your device clock (Date.now()), and displays the exact time remaining or when it expired.

Can I verify RS256 or asymmetric tokens?

This tool currently provides signature calculation for HS256 (HMAC SHA-256). For asymmetric algorithms (RS256, ES256), the header and payload claims are fully decoded and validated for expiration.

What are Subject Alternative Names (SANs)?

SANs specify additional hostnames (e.g. *.example.com, api.example.com, staging.example.com) protected by a single SSL/TLS certificate.

More tools