Skip to content

JWT Debugger — Go source

Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.

This is the Go implementation — the same logic the interactive tool runs, in a shareable, citable form.

// Package jwt is the Go twin of CosmoDev's src/lib/jwt.ts (dual source: the web
// lib is TypeScript, the CLI lib is Go — kept in lock-step). Pure + deterministic,
// never panics. The table-driven tests in jwt_test.go share vectors with
// src/lib/jwt.test.ts so the two implementations are held to the same contract.
//
// The TS lib is decode-only (no signature verification; the secret lives
// server-side). The twin mirrors it exactly: B64urlDecode maps a base64url
// string (a JWT header/payload segment) back to its underlying bytes as a UTF-8
// string — the URL-safe alphabet ('-'/'_') is restored to standard ('+'/'/'),
// missing '=' padding is added back, then standard base64 decodes. Invalid input
// yields a non-nil error instead of the TS throw.
package jwt

import (
	"encoding/base64"
	"strings"
)

// B64urlDecode decodes a base64url string to its underlying bytes, returned as a
// UTF-8 string. It is the Go twin of b64urlDecode() in src/lib/jwt.ts and must
// agree with it on every shared vector.
//
// The pipeline mirrors the TS lib step for step:
//  1. map the URL-safe alphabet back to standard ('-' → '+', '_' → '/'),
//  2. restore '=' padding until the length is a multiple of 4,
//  3. standard base64-decode (the Go equivalent of JS atob).
//
// Invalid input returns a non-nil error (the TS lib throws); it never panics.
func B64urlDecode(s string) (string, error) {
	// 1. URL-safe alphabet back to standard, exactly like str.replace(/-/g,'+').replace(/_/g,'/').
	standard := strings.NewReplacer("-", "+", "_", "/").Replace(s)
	// 2. restore missing '=' padding (TS: while (s.length % 4) s += '=').
	for len(standard)%4 != 0 {
		standard += "="
	}
	// 3. standard base64 decode (atob).
	data, err := base64.StdEncoding.DecodeString(standard)
	if err != nil {
		return "", err
	}
	return string(data), nil
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →