JWT Decoder & Token Inspector

Inspect & verify auth tokens

Only for iPhone

Free · In‑App Purchases · Designed for iPhone. Not verified for macOS.

iPhone

Paste a JWT and see it decoded, its claims read out and its signature verified — all on your device, never on a server. Decode any JSON Web Token in a second — paste it in and JWTPeek splits it into a colour-coded header, payload and signature, pretty-printed and ready to copy. It is the fast, private way to read and inspect a JWT without pasting it into a random website. Most online JWT decoders make you send a sensitive bearer token to a server. JWTPeek does everything locally with Apple's CryptoKit — your token is decoded and verified right on your iPhone and never touches a server, a log or the network. WHAT YOU GET - A clean three-part breakdown of any token: header, payload and signature, each Base64URL-decoded and pretty-printed - Every claim laid out and labelled — issuer, subject, audience and your own custom claims - exp, nbf and iat shown as real human dates, with a live expiry countdown so you know instantly if a token is still valid - One-tap HMAC signature verification with HS256, HS384 or HS512 — enter your secret (plain or Base64) and see match or mismatch - Clear alg:none warnings so you never trust an unsigned token by mistake - A saved history of recently decoded tokens, on this device, so you can reopen any of them in a single tap PERFECT FOR - Backend and API developers debugging authentication and login flows - Engineers building with OAuth 2.0 and OpenID Connect - QA and security testers inspecting bearer tokens and claims - Anyone who needs to quickly check when a token expires WHY NOT JUST USE A WEBSITE? Because pasting a real access token into a browser tab sends it over the internet to a third party. A JWT is a bearer credential — whoever holds it can use it. JWTPeek keeps every token on your device, so you can inspect production tokens without leaking them. PRIVACY 100% on-device. Every token is decoded and verified locally with CryptoKit. Nothing is ever uploaded, logged, or sent to any server. There are no accounts and no tracking. FULL ACCESS JWTPeek Premium unlocks the full toolkit: on-device HMAC signature verification (HS256, HS384, HS512) and the complete security reference. Choose the plan that fits you: - Weekly - Yearly (best value) - Lifetime — pay once, yours forever Subscriptions auto-renew until cancelled; Lifetime is a single one-time purchase. Paste your first token and see it decoded in seconds. Terms of Use (EULA): https://web-levi.web.app/terms Privacy Policy: https://web-levi.web.app/privacy-policy Questions? tphuc.work@gmail.com

  • This app hasn’t received enough ratings or reviews to display an overview.

Bug fixes and performance improvements.

The developer, Phuc Pham, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .

  • Data Not Collected

    The developer does not collect any data from this app.

    Privacy practices may vary, for example, based on the features you use or your age. Learn More

    The developer has not yet indicated which accessibility features this app supports. Learn More

    Seller
    • Phuc Pham
    Size
    • 4.8 MB
    Category
    • Developer Tools
    Compatibility
    Requires iOS 17.0 or later.
    • iPhone
      Requires iOS 17.0 or later.
    • Mac
      Requires macOS 14.0 or later and a Mac with Apple M1 chip or later.
    • Apple Vision
      Requires visionOS 1.0 or later.
    Languages
    • English
    Age Rating
    4+
    In-App Purchases
    Yes
    • Base64 Payload Kit Lifetime $29.99
    • Bearer Auth Debug Weekly $2.99
    • OAuth Claim Toolkit Yearly $14.99
    Copyright
    • © 2026 Phuc Pham