Skip to content

JWT Debugger — Ruby source

Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.

This is the Ruby implementation — the same logic the interactive tool runs, in a shareable, citable form.

# JWT base64url decoding helper — Ruby port of the jwt tool.

module Jwt
  # Decode a base64url segment (JWT header/payload) to text. unpack1("m0") is
  # Ruby's strict base64: it raises ArgumentError on any character outside
  # the standard alphabet (after the URL-safe mapping) — the TS throw
  # analogue. Plain unpack("m") would silently skip bad characters instead.
  def self.b64url_decode(str)
    # 1. URL-safe alphabet -> standard base64 alphabet.
    s = str.tr('-_', '+/')

    # 2. Restore stripped '=' padding so the length is a multiple of 4.
    raise ArgumentError, 'invalid base64url length' if s.length % 4 == 1
    s += '=' * ((4 - s.length % 4) % 4)

    # 3. Strict standard base64 -> bytes ("m0" validates, "m" does not).
    bytes = s.unpack1('m0')

    # 4. Bytes -> text, byte-faithful (ISO-8859-1): each byte becomes the
    #    character of the same code point, mirroring JS atob so the full
    #    0x00-0xFF byte range round-trips (UTF-8 would raise on 0x80+).
    bytes.force_encoding(Encoding::ISO_8859_1)
  end
end

# eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}
puts Jwt.b64url_decode('eyJhbGciOiJIUzI1NiJ9')

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →