Privacy

JWTEncoder.com is built so that your secrets, keys and tokens never leave your device.

Everything runs in your browser

Claims building, secret and key generation, signing and self-verification use the browser's Web Crypto API through the open-source jose library. The site is static files with a strict Content Security Policy and no third-party scripts on the tool.

What we never collect

What is stored on your device

Only harmless preferences in localStorage: theme and Simple/Advanced mode. Secrets, keys, payloads and tokens are never persisted — reload and they are gone.

“Inspect in JWTDecoder” copies the token to your clipboard and opens the decoder. Nothing is placed in the URL or sent to a server.

Analytics

If aggregate usage analytics are enabled, they record only event names (for example “JWT generated”) and non-sensitive enumerations such as the algorithm — never secrets, keys, tokens or claim values.