5 items
Decode JWTs in the popup and run security checks on the claims. Decoding is local — no tokens leave your browser. Decode A JWT And See Its Security Issues Paste a JWT or an OAuth redirect URL into the popup. The extension decodes header, payload, and signature locally and runs security checks against the claims. WHAT IT DOES - Decodes JWT header, payload, and signature using standard base64url decoding in the popup - Extracts the token from an OAuth redirect URL if you paste one (access_token, id_token, or token in the URL fragment or query) - Runs checks against the claims: alg = none detection, HMAC warning, expiration status, issued-at display, audience presence, issuer presence, subject presence HOW IT WORKS 1. Click the icon 2. Paste a JWT or OAuth redirect URL 3. See the decoded fields and security checks PRIVACY Decoding happens entirely in the popup's JavaScript context. Tokens are never transmitted. No storage, no telemetry. SUPPORT Email: support@cchk.info Privacy policy: https://extensions.cchk.info/jwt-oauth-inspector/privacy Built by Cloud Geeks, a division of Ganda Tech Services.
Apr 25, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.