JWT Debugger — Java source
Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.
This is the Java implementation — the same logic the interactive tool runs, in a shareable, citable form.
// JWT base64url decoding helper — Java (17+) port of the jwt tool.
import java.nio.charset.StandardCharsets;
import java.util.Base64;
public final class Jwt {
private Jwt() {}
// Decode a base64url segment (JWT header/payload) to text. The standard
// java.util.Base64 decoder rejects any character outside the standard
// alphabet after the URL-safe mapping — the TS throw analogue
// (IllegalArgumentException).
public static String b64urlDecode(String str) {
// 1. URL-safe alphabet -> standard base64 alphabet.
String s = str.replace('-', '+').replace('_', '/');
// 2. Restore stripped '=' padding so the length is a multiple of 4.
if (s.length() % 4 == 1) {
throw new IllegalArgumentException("invalid base64url length");
}
s = s + "=".repeat((4 - s.length() % 4) % 4);
// 3. Strict standard base64 -> bytes.
byte[] bytes = Base64.getDecoder().decode(s);
// 4. Bytes -> text, byte-faithful (ISO-8859-1): each byte becomes the
// character of the same code point, mirroring JS atob so the full
// 0x00-0xFF byte range round-trips (UTF-8 would mangle it).
return new String(bytes, StandardCharsets.ISO_8859_1);
}
public static void main(String[] args) {
// eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}
System.out.println(b64urlDecode("eyJhbGciOiJIUzI1NiJ9"));
}
}
Also available in 13 other languages
Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →