Pop plugin · Developer

Decode JWT

Decode the selected JWT and list claims such as issuer and expiry (decoding only; the signature isn’t verified).

Works with Selected textFree

How to use it

Select something, hold the right mouse button, swipe. The animation plays the steps one after another; click a step to see it again.

  1. Select a JWT
  2. Hold the right mouse buttonAbout a quarter of a second. A short click still opens the usual menu.
  3. Swipe to “Decode JWT” and let goIt sits on the ring where you put it, and it’s always in All Actions.
  4. The claims, decoded
  5. See when it expiresIn local time, with how long it has left.
  6. Copy the payload

What it does

Select a JWT to list its algorithm, issuer, subject and audience, and when it was issued, becomes valid and expires, in local time.

The expiry says whether the token has already expired, or how soon it will.

The decoded payload is shown in full and neatly formatted. Copy it, or copy the header.

It only decodes: the signature isn’t verified.

Install it

Plugins aren’t part of the Pop download. Install this one when you need it.

1From Settings

In Pop’s Settings › Actions, find “Decode JWT” under Plugins at the top and click Install. It downloads from Pop’s GitHub release in a few seconds and works right away, without a restart.

2Or from the ring

Open All Actions on the ring and search for “Decode JWT”. Plugins that aren’t installed are listed after your actions: click it to install, and it runs right away if it can handle what you selected.

3Then use it your way

Put it on the ring in Settings › Ring, give it a shortcut, or run it from Shortcuts and scripts with its link:

pop://run?plugin=jwtDecode

Uninstall it from the same list when you no longer need it: the plugin and its settings are deleted. After Pop updates, installed plugins are updated with it, and with iCloud sync on, what you install syncs to your other Macs.