Skip to content

JWT Debugger — C# source

Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.

This is the C# implementation — the same logic the interactive tool runs, in a shareable, citable form.

// JWT base64url decoding helper — C# (.NET 8) port of the jwt tool.

using System;
using System.Text;

namespace CosmoDev.Jwt;

public static class Jwt
{
    // Decode a base64url segment (JWT header/payload) to text. Convert's
    // decoder validates the standard alphabet (embedded whitespace aside)
    // and throws FormatException on anything else — the TS throw analogue.
    public static string B64urlDecode(string str)
    {
        // 1. URL-safe alphabet -> standard base64 alphabet.
        string s = str.Replace('-', '+').Replace('_', '/');

        // 2. Restore stripped '=' padding so the length is a multiple of 4.
        if (s.Length % 4 == 1) throw new FormatException("invalid base64url length");
        s += new string('=', (4 - s.Length % 4) % 4);

        // 3. Strict standard base64 -> bytes.
        byte[] bytes = Convert.FromBase64String(s);

        // 4. Bytes -> text, byte-faithful (Latin-1), mirroring JS atob so the
        //    full 0x00-0xFF byte range round-trips (UTF-8 would reject 0x80+).
        return Encoding.Latin1.GetString(bytes);
    }
}

public static class JwtDemo
{
    public static void Main()
    {
        // eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}
        Console.WriteLine(Jwt.B64urlDecode("eyJhbGciOiJIUzI1NiJ9"));
    }
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →