Paste a JSON Web Token to debug it: read its header and payload, see whether it has expired, and check an HS256 signature if you have the secret. Everything happens in this page: the token is never sent anywhere, and you can watch the Network tab to confirm it.
—
—
| — | Paste a token above. |
If the token uses HS256 and you have the shared secret, this checks it here in the browser. RS256 and ES256 need the issuer's public key and are not checked here.
Write a payload, pick a secret, and get a signed token to test your API with. Signed here with your browser's Web Crypto; nothing is sent. Use a test secret only: anyone who knows it can mint tokens your server will accept.
exp passes, a stolen token still works unless the issuer keeps a deny list.HeaderForge sets the Authorization header for the sites you choose, keeps the value in a variable like {{token}} so it stays out of your exported rules, warns you when a rule carries a credential, and shows whether the rule actually fired. Free, no analytics, no account.