Developer Tools · PRACTICAL GUIDE
Inspect API data without confusing decoding with verification
Follow a practical workflow for JSON structure, JWT claims, timestamps, hashes and regex matches while preserving the meaning of the original data.
Begin with the representation
A response body may be JSON, an encoded token, a quoted string or an HTML error. Keep the original and identify the format before editing it. A successful decode only tells you how bytes were represented; it does not establish who produced them.
Use JSON Formatter for syntax and indentation, or JSON Viewer to open branches. A numeric ID such as 9007199254740993 should not pass through a floating-point conversion just to make it readable. UtilityPilot’s JSON tools preserve number tokens.
Compare structure before explaining a change
Before: {"enabled":true,"timeout":30}
After: {"timeout":30,"enabled":false}JSON Compare reports /enabled as changed. Member order creates no difference. That result identifies a changed setting; it cannot decide whether the service owner intended it. Arrays compare by index, so an insertion can affect several positions.
Read a token with the correct trust boundary
JWT Decoder exposes JSON header and payload fields but performs no signature verification. Treat a decoded role, issuer or expiry as a claim from the token, not an authenticated fact. Verification belongs in an application using trusted keys, allowed algorithms and its issuer/audience policy.
A claim with value 1700000000 represents 2023-11-14T22:13:20Z if its unit is Unix seconds. The timestamp converter can show that instant. Choosing milliseconds for the same digits changes the meaning; inspect the source specification before converting.
Check bytes, identifiers and patterns separately
A SHA digest depends on exact UTF-8 text, including whitespace. A byte mismatch is not explained merely by two documents having the same visible text. A random UUID v4 identifies a generated item but does not fingerprint its contents or sort it by creation time.
Use number-base conversion for integer notation and Regex Tester for candidate matching rules. Neither can infer business meaning. Test a pattern against missing fields, extra punctuation and Unicode as well as the happy path.
Keep the inspection reproducible
Record the operation, options and an invented example that exhibits the problem. Copy only the result needed for the next tool; inputs are not transferred automatically or placed in share URLs. Avoid exporting real access tokens into issue reports. Reset clears the interface, while clipboard and downloaded copies remain under your control.
All these transformations run locally. For explanations beyond the implementation, consult the JWT specification and JSON Pointer. A local inspection tool is useful evidence during debugging, not a substitute for production verification or application-specific tests.
Put it into practice
Choose the tool that matches your next step. Keep an original copy and inspect the result before using it elsewhere.
JSON ViewerExplore nested keys, values and paths in a collapsible JSON tree.Data & TablesJSON CompareFind structural additions, removals and changes in two JSON documents.Data & TablesJWT DecoderRead a token’s JSON header and payload without claiming verification.Developer ToolsUnix Timestamp ConverterConvert epoch seconds or milliseconds and explicitly zoned dates.Developer ToolsSHA Hash GeneratorFingerprint exact UTF-8 text with SHA-256, SHA-384 or SHA-512.Developer ToolsRegex TesterInspect JavaScript regex matches, capture groups and positions.Developer ToolsUUID GeneratorGenerate one or a batch of random version-4 UUIDs.Developer ToolsNumber Base ConverterConvert exact signed integers between binary, octal, decimal and hex.Developer ToolsBase64 encoder and decoderConvert text to or from Base64 representation.Web & Publishing