Skip to content

JWT Debugger — TypeScript source

Decode a JSON Web Token and inspect its header and payload as pretty JSON, with exp/iat claim awareness and an expiry badge. Runs entirely in your browser.

This is the TypeScript implementation — the same logic the interactive tool runs, in a shareable, citable form.

/**
 * JWT decoding helpers - pure logic extracted from JwtDebugger.tsx.
 * Decodes only (no signature verification); the secret lives server-side.
 */

/**
 * Decode a base64url string to UTF-8, converting the URL-safe alphabet
 * (`-`/`_`) back to standard base64 (`+`/`/`) and restoring padding.
 * Throws on invalid base64 input (propagated from `atob`).
 */
export function b64urlDecode(str: string): string {
  let s = str.replace(/-/g, '+').replace(/_/g, '/');
  while (s.length % 4) s += '=';
  return atob(s);
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →