JWT Debugger — Ruby source
Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.
This is the Ruby implementation — the same logic the interactive tool runs, in a shareable, citable form.
# JWT base64url decoding helper — Ruby port of the jwt tool.
module Jwt
# Decode a base64url segment (JWT header/payload) to text. unpack1("m0") is
# Ruby's strict base64: it raises ArgumentError on any character outside
# the standard alphabet (after the URL-safe mapping) — the TS throw
# analogue. Plain unpack("m") would silently skip bad characters instead.
def self.b64url_decode(str)
# 1. URL-safe alphabet -> standard base64 alphabet.
s = str.tr('-_', '+/')
# 2. Restore stripped '=' padding so the length is a multiple of 4.
raise ArgumentError, 'invalid base64url length' if s.length % 4 == 1
s += '=' * ((4 - s.length % 4) % 4)
# 3. Strict standard base64 -> bytes ("m0" validates, "m" does not).
bytes = s.unpack1('m0')
# 4. Bytes -> text, byte-faithful (ISO-8859-1): each byte becomes the
# character of the same code point, mirroring JS atob so the full
# 0x00-0xFF byte range round-trips (UTF-8 would raise on 0x80+).
bytes.force_encoding(Encoding::ISO_8859_1)
end
end
# eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}
puts Jwt.b64url_decode('eyJhbGciOiJIUzI1NiJ9')
Also available in 13 other languages
Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →