JWT Decoder & Token Inspector
Inspect & verify auth tokens
Only for iPhone
Free · In‑App Purchases · Designed for iPhone. Not verified for macOS.
iPhone
Paste a JWT and see it decoded, its claims read out and its signature verified — all on your device, never on a server.
Decode any JSON Web Token in a second — paste it in and JWTPeek splits it into a colour-coded header, payload and signature, pretty-printed and ready to copy. It is the fast, private way to read and inspect a JWT without pasting it into a random website.
Most online JWT decoders make you send a sensitive bearer token to a server. JWTPeek does everything locally with Apple's CryptoKit — your token is decoded and verified right on your iPhone and never touches a server, a log or the network.
WHAT YOU GET
- A clean three-part breakdown of any token: header, payload and signature, each Base64URL-decoded and pretty-printed
- Every claim laid out and labelled — issuer, subject, audience and your own custom claims
- exp, nbf and iat shown as real human dates, with a live expiry countdown so you know instantly if a token is still valid
- One-tap HMAC signature verification with HS256, HS384 or HS512 — enter your secret (plain or Base64) and see match or mismatch
- Clear alg:none warnings so you never trust an unsigned token by mistake
- A saved history of recently decoded tokens, on this device, so you can reopen any of them in a single tap
PERFECT FOR
- Backend and API developers debugging authentication and login flows
- Engineers building with OAuth 2.0 and OpenID Connect
- QA and security testers inspecting bearer tokens and claims
- Anyone who needs to quickly check when a token expires
WHY NOT JUST USE A WEBSITE?
Because pasting a real access token into a browser tab sends it over the internet to a third party. A JWT is a bearer credential — whoever holds it can use it. JWTPeek keeps every token on your device, so you can inspect production tokens without leaking them.
PRIVACY
100% on-device. Every token is decoded and verified locally with CryptoKit. Nothing is ever uploaded, logged, or sent to any server. There are no accounts and no tracking.
FULL ACCESS
JWTPeek Premium unlocks the full toolkit: on-device HMAC signature verification (HS256, HS384, HS512) and the complete security reference. Choose the plan that fits you:
- Weekly
- Yearly (best value)
- Lifetime — pay once, yours forever
Subscriptions auto-renew until cancelled; Lifetime is a single one-time purchase.
Paste your first token and see it decoded in seconds.
Terms of Use (EULA): https://web-levi.web.app/terms
Privacy Policy: https://web-levi.web.app/privacy-policy
Questions? tphuc.work@gmail.com
Ratings & Reviews
- This app hasn’t received enough ratings or reviews to display an overview.
Bug fixes and performance improvements.
Subscriptions
In-App Purchases
The developer, Phuc Pham, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .
Data Not Collected
The developer does not collect any data from this app.
Accessibility
The developer has not yet indicated which accessibility features this app supports. Learn More
Information
- Seller
- Phuc Pham
- Size
- 4.8 MB
- Category
- Developer Tools
- Compatibility
Requires iOS 17.0 or later.
- iPhone
Requires iOS 17.0 or later. - Mac
Requires macOS 14.0 or later and a Mac with Apple M1 chip or later. - Apple Vision
Requires visionOS 1.0 or later.
- iPhone
- Languages
- English
- Age Rating
4+
- 4+
- In-App Purchases
Yes
- Base64 Payload Kit Lifetime $29.99
- Bearer Auth Debug Weekly $2.99
- OAuth Claim Toolkit Yearly $14.99
- Copyright
- © 2026 Phuc Pham
