Privacy
JWTEncoder.com is built so that your secrets, keys and tokens never leave your device.
Everything runs in your browser
Claims building, secret and key generation, signing and self-verification use the browser's Web Crypto API through the open-source jose library. The site is static files with a strict Content Security Policy and no third-party scripts on the tool.
What we never collect
- Signing secrets, private keys or generated keys
- JWTs, headers or payloads
- Subject, issuer, audience or custom claim values
What is stored on your device
Only harmless preferences in localStorage: theme and Simple/Advanced mode. Secrets, keys, payloads and tokens are never persisted — reload and they are gone.
Moving tokens to JWTDecoder
“Inspect in JWTDecoder” copies the token to your clipboard and opens the decoder. Nothing is placed in the URL or sent to a server.
Analytics
If aggregate usage analytics are enabled, they record only event names (for example “JWT generated”) and non-sensitive enumerations such as the algorithm — never secrets, keys, tokens or claim values.