Skip to content

JWT Debugger — Java source

Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.

This is the Java implementation — the same logic the interactive tool runs, in a shareable, citable form.

// JWT base64url decoding helper — Java (17+) port of the jwt tool.

import java.nio.charset.StandardCharsets;
import java.util.Base64;

public final class Jwt {

    private Jwt() {}

    // Decode a base64url segment (JWT header/payload) to text. The standard
    // java.util.Base64 decoder rejects any character outside the standard
    // alphabet after the URL-safe mapping — the TS throw analogue
    // (IllegalArgumentException).
    public static String b64urlDecode(String str) {
        // 1. URL-safe alphabet -> standard base64 alphabet.
        String s = str.replace('-', '+').replace('_', '/');

        // 2. Restore stripped '=' padding so the length is a multiple of 4.
        if (s.length() % 4 == 1) {
            throw new IllegalArgumentException("invalid base64url length");
        }
        s = s + "=".repeat((4 - s.length() % 4) % 4);

        // 3. Strict standard base64 -> bytes.
        byte[] bytes = Base64.getDecoder().decode(s);

        // 4. Bytes -> text, byte-faithful (ISO-8859-1): each byte becomes the
        //    character of the same code point, mirroring JS atob so the full
        //    0x00-0xFF byte range round-trips (UTF-8 would mangle it).
        return new String(bytes, StandardCharsets.ISO_8859_1);
    }

    public static void main(String[] args) {
        // eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}
        System.out.println(b64urlDecode("eyJhbGciOiJIUzI1NiJ9"));
    }
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →