⚯ DECODE & INSPECT
// JWT & TOKEN INSPECTOR

JWT / Token Inspector

Paste a JWT or Bearer token — the tool decodes the header + claims, flags weaknesses (alg:none, guessable HS256 secret, expiry, kid/jku injection), and maps Microsoft Entra / Azure AD claims (scopes, app roles, Global Admin) to abuse potential. Decoded locally — nothing leaves your browser.

Paste a JWT to decode & inspect
Header + claims, weakness findings, and Azure/Entra claim mapping