Privacy

JWTDecoder.com is built so that your tokens and keys never leave your device.

Everything runs in your browser

Decoding, signature verification (via the browser's Web Crypto API), claim validation, security analysis and code generation all happen locally. The site is a set of static files; there is no application server that could receive your data.

What we never collect

Tokens are never placed in URLs, cookies or local storage, and input fields opt out of browser grammar-checking extensions.

What is stored on your device

Only harmless display preferences in localStorage: your theme and timestamp format. Clearing site data removes them.

Network requests you initiate

If you use Load a JWKS from a URL or Discover from issuer, your browser requests that URL directly. Only the key set (or discovery document) is requested; your token is not sent.

Tokens move between the two sites only when you click a button, via your clipboard — never through URLs or servers.

Analytics

If aggregate usage analytics are enabled, they record only event names (for example “decode succeeded”) and non-sensitive enumerations such as the algorithm name — never token contents or keys.