JWT Decoder

korinat.com

Privacy Policy

Privacy Policy

Updated 2 October 2026

This page describes the JWT Decoder. The token is decoded in your browser. There are no accounts, ads, cookies set by this page, or client-side tracking. This tool does not verify signatures and does not send the token to a server.

The token never leaves the browser

The JWT and the decoded header, payload, and signature stay on your device. They are not sent for decoding or storage. Open uses the local File API. Save is a browser download. Nothing is uploaded. The token is not written to LocalStorage, sessionStorage, or a cookie.

No accounts, no content logs

There are no user accounts. This Worker does not keep a server-side log of your token. The Content-Security-Policy sets connect-src 'none', so the page cannot make network requests that would send your token elsewhere.

Hosting and connection data

This site is served from Cloudflare Workers. Cloudflare, Inc. is a recipient of technical connection data that is generated when your browser requests the page, including IP address, User-Agent, and TLS metadata. Cloudflare processes that data to deliver the site and operate its network. The JWT and the decoded panels are not sent to Cloudflare for processing.

Typefaces (IBM Plex Sans and IBM Plex Mono) are self-hosted on this Worker. The page does not load fonts or other resources from Google or from other third-party origins.

Audience measurement

To count page views we record request totals server-side in the Cloudflare Workers Analytics Engine. No JavaScript beacon is loaded, and we do not store or read cookies or similar information on your device for this purpose. Section 25 TDDDG does not apply. The JWT and the decoded panels stay on your device; they are never transmitted, stored, or analysed in the Analytics Engine. The Content-Security-Policy remains connect-src 'none'. If the VISITS binding is not configured, the counter is skipped.

We process request counts for the paths retrieved, together with country, a browser family derived from the User-Agent (UA family), referrer host, and hostname. We do not store raw IP addresses, the full User-Agent string, or JWT contents. The recipient is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as processor for hosting and the Analytics Engine.

Legal basis: Article 6(1)(f) GDPR (legitimate interest in audience measurement and operating the site).

Retention: Analytics Engine records are stored for three months and then deleted. We do not keep a longer archive.

Transfers to the United States: Cloudflare is a recipient in a third country. Transfers rely on the EU-US Data Privacy Framework and/or the European Commission’s standard contractual clauses.

Your rights under Articles 15–21 GDPR: access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests (Article 21 GDPR). Because we do not store a lasting identifier, we usually cannot link and delete individual past requests to you. You may lodge a complaint with a data protection supervisory authority.

Controller

Arne Schilling, Martin-Luther-Str. 12, 15517 Fürstenwalde/Spree, Germany, info@korinat.com

← JWT Decoder