Tokens & Auth
Inspect and debug the tokens behind modern authentication: JWTs, JWKs, and OAuth values. Tokens are decoded in your browser, which matters because a live token is a credential.
- JWK & JWKS ViewerInspect a JWK or JWKS: key type, use, alg, kid, key size or curve, RFC 7638 thumbprint, and warnings for weak keys, private material, and duplicate kids.
- JWT Decoder & VerifierDecode a JSON Web Token, see an expiry timeline, spot insecure settings, and verify HS, RS, PS, ES, and EdDSA signatures with a secret, PEM, JWK, or JWKS.
- JWT Encoder & SignerCreate and sign a JWT from a header and payload. Supports HS256 to HS512, RS, PS, ES, and EdDSA, with claim helpers and key generation, all in your browser.
- OAuth Authorization URL BuilderBuild or parse an OAuth 2.0 and OpenID Connect authorization URL with scope, state, nonce, PKCE, and extra parameters, and get warnings about risky settings.
- PKCE Code Verifier & Challenge GeneratorGenerate a PKCE code_verifier of 43 to 128 characters and its S256 code_challenge for OAuth 2.0 and OpenID Connect, using your browser's secure random source.
- OAuth Scope Parser & FormatterParse, dedupe, sort, and reformat OAuth scopes between space, comma, JSON, and URL-encoded forms, with explanations of the standard OpenID Connect scopes.
- OIDC Claims Reference & ID Token CheckerLook up standard OpenID Connect claims and check an ID token's iss, aud, azp, exp, nonce, auth_time, at_hash, and c_hash against what you expect.
- TOTP Generator & ValidatorGenerate live time-based one-time passwords with a countdown, and validate a code with a drift window. Supports SHA1, SHA256, SHA512, 6 to 8 digits, and custom periods.
- HOTP Generator & ValidatorGenerate counter-based one-time passwords per RFC 4226 and validate a code against a look-ahead window to resynchronize a counter.
- otpauth:// URI Parser, Builder & QR CodeParse an otpauth:// URI into issuer, account, and secret, or build one and get a QR code for an authenticator app. The secret never leaves your browser.