|
| 1 | +# JWT for Vicinae |
| 2 | + |
| 3 | +Decode a JSON Web Token from your clipboard and read it without leaving the keyboard. |
| 4 | +An extension for [Vicinae](https://vicinae.com). |
| 5 | + |
| 6 | +<img src=".github/assets/screenshot.png" alt="Decoded payload, signature verification and a diff between two tokens"> |
| 7 | + |
| 8 | +## Features |
| 9 | + |
| 10 | +### Decode |
| 11 | + |
| 12 | +Takes the token from the clipboard, or as a command argument. Arrow keys move between |
| 13 | +sections, Enter acts on the one you are on. |
| 14 | + |
| 15 | +| Section | Enter | Shows | |
| 16 | +|---|---|---| |
| 17 | +| Payload | Copy JSON | Claims annotated with their registered names, timestamps as dates | |
| 18 | +| Header | Copy JSON | The JOSE header, annotated the same way | |
| 19 | +| Signature | Verify | The verdict, the algorithm, the issuer's discovery document | |
| 20 | +| Diff | Copy patch | A unified diff against the previously decoded token | |
| 21 | +| Specs | Open RFC 7519 | RFC 7519, RFC 7515, RFC 9068, OpenID Connect Core | |
| 22 | + |
| 23 | +### Expiry |
| 24 | + |
| 25 | +Reads the clipboard and shows a HUD: |
| 26 | +`Active - Aug 30, 2026, 2:52 AM - in 2 hours - web-app - 1234567890`. |
| 27 | + |
| 28 | +## Verifying |
| 29 | + |
| 30 | +Verification runs only when you ask for it, and only talks to the token's own issuer. |
| 31 | + |
| 32 | +* **RS, ES, PS**: the `iss` claim leads to the discovery document, then the JWKS, then |
| 33 | + the key matching `kid`. Both requests must be https, and a redirect off https is |
| 34 | + refused, since a tampered key set makes a forged token look verified. |
| 35 | +* **HS256/384/512**: a form asks for the shared secret. It is tried as raw text and as |
| 36 | + base64url, the result says which matched, and it is never stored. |
| 37 | + |
| 38 | +## Install |
| 39 | + |
| 40 | +Open the Vicinae launcher, run **Store**, and search for JWT. |
| 41 | + |
| 42 | +## Source |
| 43 | + |
| 44 | +Developed at [balazsorban44/vicinae-jwt](https://github.com/balazsorban44/vicinae-jwt). |
| 45 | + |
| 46 | +## License |
| 47 | + |
| 48 | +MIT |
0 commit comments