Skip to content

Commit ccbffa3

Browse files
feat: add JWT extension (#369)
1 parent de926d2 commit ccbffa3

21 files changed

Lines changed: 2409 additions & 0 deletions
423 KB
Loading

‎extensions/jwt/LICENSE‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
MIT License
2+
3+
Copyright (c) 2026 Balázs Orbán
4+
5+
Permission is hereby granted, free of charge, to any person obtaining a copy
6+
of this software and associated documentation files (the "Software"), to deal
7+
in the Software without restriction, including without limitation the rights
8+
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
9+
copies of the Software, and to permit persons to whom the Software is
10+
furnished to do so, subject to the following conditions:
11+
12+
The above copyright notice and this permission notice shall be included in all
13+
copies or substantial portions of the Software.
14+
15+
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
16+
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
17+
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
18+
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
19+
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
20+
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
21+
SOFTWARE.

‎extensions/jwt/README.md‎

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
# JWT for Vicinae
2+
3+
Decode a JSON Web Token from your clipboard and read it without leaving the keyboard.
4+
An extension for [Vicinae](https://vicinae.com).
5+
6+
<img src=".github/assets/screenshot.png" alt="Decoded payload, signature verification and a diff between two tokens">
7+
8+
## Features
9+
10+
### Decode
11+
12+
Takes the token from the clipboard, or as a command argument. Arrow keys move between
13+
sections, Enter acts on the one you are on.
14+
15+
| Section | Enter | Shows |
16+
|---|---|---|
17+
| Payload | Copy JSON | Claims annotated with their registered names, timestamps as dates |
18+
| Header | Copy JSON | The JOSE header, annotated the same way |
19+
| Signature | Verify | The verdict, the algorithm, the issuer's discovery document |
20+
| Diff | Copy patch | A unified diff against the previously decoded token |
21+
| Specs | Open RFC 7519 | RFC 7519, RFC 7515, RFC 9068, OpenID Connect Core |
22+
23+
### Expiry
24+
25+
Reads the clipboard and shows a HUD:
26+
`Active - Aug 30, 2026, 2:52 AM - in 2 hours - web-app - 1234567890`.
27+
28+
## Verifying
29+
30+
Verification runs only when you ask for it, and only talks to the token's own issuer.
31+
32+
* **RS, ES, PS**: the `iss` claim leads to the discovery document, then the JWKS, then
33+
the key matching `kid`. Both requests must be https, and a redirect off https is
34+
refused, since a tampered key set makes a forged token look verified.
35+
* **HS256/384/512**: a form asks for the shared secret. It is tried as raw text and as
36+
base64url, the result says which matched, and it is never stored.
37+
38+
## Install
39+
40+
Open the Vicinae launcher, run **Store**, and search for JWT.
41+
42+
## Source
43+
44+
Developed at [balazsorban44/vicinae-jwt](https://github.com/balazsorban44/vicinae-jwt).
45+
46+
## License
47+
48+
MIT
25 KB
Loading
25 KB
Loading
Lines changed: 13 additions & 0 deletions
Loading

0 commit comments

Comments
 (0)