// JWT & TOKEN INSPECTOR
JWT / Token Inspector
Paste a JWT or Bearer token — the tool decodes the header + claims, flags weaknesses (alg:none, guessable HS256 secret, expiry, kid/jku injection), and maps Microsoft Entra / Azure AD claims (scopes, app roles, Global Admin) to abuse potential. Decoded locally — nothing leaves your browser.
⚿
Paste a JWT to decode & inspect
Header + claims, weakness findings, and Azure/Entra claim mapping