5 ms·
Show HN: Jwt.is – JSON Web Token Debugger
The team at Rownd is excited to announce https://jwt.is https://jwt.is, an updated take on JSON Web Token debugging.
Like most developers, we've used jwt.io for years, but it lacks a number of useful features that would make it even more convenient. We're building on the shoulders of those who've come before us. :-)
In addition to the basic JWT decoding and signature verification, we've added things like:
- Verification using JWK endpoints
- Locally stored history of tokens and keys
- Verification for EdDSA signatures
- Detection of common token providers (e.g., Google, Apple, etc)
- Dark mode!
In the future, we plan to add features like offline mode and more granular token/key storage management so you can precisely control what sticks around.
Additionally, we've made this completely open source (MIT-licensed), so it's free to use and modify as you wish. And of course, contributions are always welcomed!
Let us know what you think!
- rgthelen 3y ago[dead]
- mbrameld 3y agoLooks a lot like https://jwt.io/ https://jwt.io/
- st0le 3y agoalso https://jwt.ms https://jwt.ms (fully client side, hosted by Microsoft)
- jamietanna 3y agoAlso https://token.dev https://token.dev which supports JWT and PASETO tokens
- mhamann 3y agohttps://jwt.is https://jwt.is is also fully client-side
- IceDane 3y agoI'm sorry.. but is this for real? This is like an afternoon of work, and it's more or less a carbon copy of the existing tools. No one will care about any of the features you are describing. How much time do you think people spend on debugging JWTs? Then you also went and added AI integration of all things. This lets me wait 10 seconds to let GPT tell the definitions for each part of the JWT, which don't change. You could have just replaced it with a map from the claims to their purpose as defined by the RFC(https://datatracker.ietf.org/doc/html/rfc7519#section-4.1.3 https://datatracker.ietf.org/doc/html/rfc7519#section-4.1.3). Not to mention how unfathomably silly it is to talk about security and whatnot and then just send people's JWTs off to some third party.
- shagmin 3y agoThe website was probably created as a subtle way to promote their startup.
- deleted 3y ago[deleted]
- tentacleuno 3y ago> The website was probably created as a subtle way to promote their startup. Seems fair, TBH. The AI recommends "Rownd", which it has clearly been programmed to do. > Solutions like Rownd can assist by simplifying and securing JWT management, ensuring that developers can focus on building their applications with increased efficiency and security.
- mhamann 3y agoAuth0/Okta uses jwt.io to promote themselves, so why shouldn't we do the same? ;-) But this was also more about scratching an itch that we had internally where similar tools didn't support all of the features we wanted them to. So, we wrote our own. Thanks for checking it out!
- tentacleuno 3y ago> This lets me wait 10 seconds to let GPT tell the definitions for each part of the JWT, which don't change. Yeah, that's lost on me. Why not embed it as a string? Seems quite lazy, as the current solution would presumably eat up all their OpenGPT credits. That, and I would have preferred an explainer from someone who understands JWT. Another obvious disadvantage of using AI is that the response can change over time, so it has the potential to hallucinate. > This is like an afternoon of work, and it's more or less a carbon copy of the existing tools. No one will care about any of the features you are describing. How much time do you think people spend on debugging JWTs? This seems a bit dismissive, though. Let's see how many people use it before making broad judgements like that. It comes across as rude and unnecessary.
- eternityforest 3y agoI think it's great, having known good, easy to use tools for common tech is great. But the ChatGPT button seems highly unnecessary. It doesn't seem to do anything a madlibs style fill in the blank template couldn't do in milliseconds.
- mhamann 3y agoThanks! Yeah, the GPT stuff was just a fun easter egg. :-D
- physicsguy 3y agoLooks nice, but pretty printing the output of the JSON is a must. I do like how you can paste the JWK URL for validation, not seen that elsewhere.
- mhamann 3y agoThanks! We have a few improvements to make around copy/paste stuff, array printing, etc. Thanks for the feedback!
- adriaanb 3y agoThanks for this. Bookmarked!
- jamietanna 3y agoMight be worth having a clearer "don't put production credentials into random websites" warning (previous discussion: https://news.ycombinator.com/item?id=24352360 https://news.ycombinator.com/item?id=24352360)
- rachelradulo 3y agoHey thanks for the feedback! We added a note under the encoded section to address this - do you think that helps?
- jamietanna 3y agoOut of interest, could jwt.io not be amended to do the same things? Last I saw it was Open Source, too. Or was there something you thought/were told wouldn't be accepted?
- mhamann 3y agoYes, it certainly could be; however, it would be up to the maintainers of that project whether to accept contributions. "Competition" is good for everyone though. Maybe they'll adopt some of our ideas. :-D
- tentacleuno 3y agoHm, I don't think this is working. The JavaScript throws a "Uncaught (in promise) be: Failed to base64url decode the signature" error, but the website says the signature is verified. Furthermore, if you enter the wrong key (just made a key on jwt.io, copied it into here, and entered the wrong key), it still says the signature is verified.
- mhamann 3y agoSorry about that--always a few bugs in the first rev. It's working now!
- T3RMINATED 3y ago[dead]