Privacy
JWTDecoder.com is built so that your tokens and keys never leave your device.
Everything runs in your browser
Decoding, signature verification (via the browser's Web Crypto API), claim validation, security analysis and code generation all happen locally. The site is a set of static files; there is no application server that could receive your data.
What we never collect
- JWTs, headers, payloads or signatures
- HMAC secrets, private keys, public keys, certificates or JWKS contents
- Issuer, subject, audience or any other claim value
Tokens are never placed in URLs, cookies or local storage, and input fields opt out of browser grammar-checking extensions.
What is stored on your device
Only harmless display preferences in localStorage: your theme and timestamp format. Clearing site data removes them.
Network requests you initiate
If you use Load a JWKS from a URL or Discover from issuer, your browser requests that URL directly. Only the key set (or discovery document) is requested; your token is not sent.
Moving tokens between JWTDecoder and JWTEncoder
Tokens move between the two sites only when you click a button, via your clipboard — never through URLs or servers.
Analytics
If aggregate usage analytics are enabled, they record only event names (for example “decode succeeded”) and non-sensitive enumerations such as the algorithm name — never token contents or keys.