Skip to content

JWT Debugger — Kotlin source

Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.

This is the Kotlin implementation — the same logic the interactive tool runs, in a shareable, citable form.

// JWT base64url decoding helper — Kotlin port of the jwt tool.

import java.util.Base64

object Jwt {
    // Decode a base64url segment (JWT header/payload) to text. The standard
    // java.util.Base64 decoder rejects any character outside the standard
    // alphabet after the URL-safe mapping — the TS throw analogue
    // (IllegalArgumentException from require / decode).
    fun b64urlDecode(str: String): String {
        // 1. URL-safe alphabet -> standard base64 alphabet.
        var s = str.replace('-', '+').replace('_', '/')

        // 2. Restore stripped '=' padding so the length is a multiple of 4.
        require(s.length % 4 != 1) { "invalid base64url length" }
        s += "=".repeat((4 - s.length % 4) % 4)

        // 3. Strict standard base64 -> bytes.
        val bytes = Base64.getDecoder().decode(s)

        // 4. Bytes -> text, byte-faithful (ISO-8859-1): each byte becomes the
        //    character of the same code point, mirroring JS atob so the full
        //    0x00-0xFF byte range round-trips (UTF-8 would mangle it).
        return String(bytes, Charsets.ISO_8859_1)
    }
}

// eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}
fun main() {
    println(Jwt.b64urlDecode("eyJhbGciOiJIUzI1NiJ9"))
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →