JWT Decoder & Debugger is a secure, developer-focused utility for decoding, inspecting, and validating JSON Web Tokens (JWT) directly on your Android device.
Whether you are debugging OAuth 2.0 and OpenID Connect (OIDC) authentication flows, inspecting API bearer tokens, or testing cryptographic signatures, this app provides real-time analysis with an emphasis on speed and data privacy.
100% PRIVATE & OFFLINE
Your authentication credentials, tokens, and cryptographic secrets never leave your device. All parsing, Base64Url decoding, formatting, and signature checks run locally on-device without any external server transmission.
KEY FEATURES
• Instant Token Decoding
Paste any standard JWT format (header.payload.signature) to view color-coded, syntax-highlighted JSON trees for both Header and Payload.
• Automatic Claim Inspection
Automatically translates UNIX timestamps (exp, nbf, iat) into your local time zone. Easily check expiration countdowns, token validity windows, issuer (iss), audience (aud), and subject (sub) claims.
• Cryptographic Signature Verification
Verify HMAC and asymmetric signatures to confirm token authenticity and detect tampering:
- HMAC: HS256, HS384, HS512 (using custom secret keys or passphrases)
- RSA: RS256, RS384, RS512 (using public keys / PEM format)
- ECDSA: ES256, ES384, ES512
• Security Vulnerability Audit
Detect common token misconfigurations and security risks, including "none" algorithm vulnerabilities, expired tokens, weak HMAC secrets, and mismatched algorithm headers.
• JWT Generator & Signer
Create custom JWT payloads for testing API endpoints. Customize claims, set expiration intervals, select signing algorithms, and output valid tokens ready for Postman or curl.
• Token Comparison (Diff Tool)
Compare two JWTs side by side to quickly diagnose discrepancies between access tokens, refresh tokens, and staging vs. production credentials.
• Token History & Favorites
Organize previously analyzed tokens locally for quick reference during debugging sessions, with the ability to clear history at any time.
BUILT FOR DEVELOPERS & SECURITY PROFESSIONALS
- Backend developers testing API authentication
- Mobile app engineers verifying token storage and expiration handling
- DevOps and security engineers auditing OAuth2, Supabase, Firebase, Auth0, Okta, and Keycloak integrations
- QA testers validating authorization scopes and role-based claims
Optimize your development workflow with a fast, offline, and privacy-respecting JWT debugging utility.
Decode, verify, and debug JSON Web Tokens offline with signature validation.