// micro-tool
JWT Security Auditor
Decode and deeply audit a JSON Web Token for alg-confusion, header-injection, expiry, and data-leak weaknesses. Offline — your token is parsed in memory only and is never stored, logged, or signature-checked.
How to use JWT Security Auditor
Manual & worked example — inputs, output, limits, what it does not do, and a worked example.
Open the reference →