Look in Your Own Browser: Which Tokens Are Really There – Simply Explained
Picture your browser as having a drawer. Every website you log into drops a little ID card in there so it recognizes you next time. That’s convenient. The trouble is, nobody ever looks in that drawer again, and nothing ever clears it out.
That this is more than a triviality is shown by a real story. Security researchers found stored ChatGPT logins on more than 100,000 devices, collected by malware. The striking part: nobody broke into the company. The software simply searched through people’s browsers and took whatever was lying in the drawer. The server was never the problem. The weakest link sat on the users’ own devices.
That shifts the question: not “is the provider secure enough?” but “what’s actually sitting in my own browser?”
Open the drawer
The nice thing is, you can look for yourself. On a page where you’re logged in, press F12. That opens the browser’s developer tools, a kind of look behind the scenes. There’s an area called “Local Storage”, and that’s exactly this drawer.
Many of the entries are something called a JWT, spelled out a JSON Web Token. That’s the little ID card from before. And here’s the surprise: you can read it. Just like that, in plain text. It says who you are and what you’re allowed to do, without you having to decrypt anything.
A JWT is signed, not secret. It’s sealed so nobody can forge it, but anyone who gets hold of it can read it. That’s not a bug, it’s on purpose. You just ought to know it works that way.
Why not everything at once
Now you might think: if a piece of malware in the browser can read one drawer, it simply reads all of them at once. But it can’t. Every website has its own locked drawer, and none can reach into another’s. An attacker who hijacks a single page gets only that one drawer, not the whole cabinet.
There’s only one way to see everything at once: not through the websites, but through the files on the hard drive. Because in the end all these drawers sit as files on your computer. Whoever reads those directly bypasses the whole separation, because they don’t ask the browser at all, they just read the disk.
That’s exactly what malware does once it’s on your machine. And it’s also exactly what a little tool I built with Claude does, to look into my own drawer. The difference isn’t the technique. The difference is: my inventory stays with me, a thief ships the loot home. It’s the difference between “I’m tidying my own drawer” and “someone is breaking into my place”.
Most of it is old clutter
The tool found a few thousand of these ID cards. That sounds like a disaster, but almost all of it is long-expired junk. And here’s the important point, the one you mustn’t fudge:
The browser never throws away old cards on its own. This drawer has no expiry date and no cleaning staff. Whatever goes in stays in, often for years, especially in browser profiles you barely use anymore. Even if you scrub the browser clean, you only remove your own copy. A card a thief has already skimmed keeps working elsewhere until the website itself declares it invalid.
So “thousands of tokens found” sounds dramatic but means almost nothing. The question isn’t how many, but which ones are still alive.
Same card, completely different worth
Because two of these cards can look exactly alike and yet mean the opposite. One is public on purpose, a kind of business card anyone may see. The other is a master key that lets you back in again and again, and it’s lying out in the open in the drawer.
Same look, opposite meaning. That’s why “found a token, so it’s a leak” is plain wrong about half the time. What matters isn’t what the card looks like, but where it lies and what it can do.
What isn’t in the drawer
The most interesting thing may be what the tool doesn’t find. Your most important logins, at Google or Microsoft for instance, don’t show up at all. Not because these services have no cards, but because they keep theirs somewhere else entirely, somewhere the tool can’t reach.
That’s a backwards picture: the dangerous thing lies open in the drawer, the well-protected thing hides. Why that is, and what you can actually do about it, comes in the next part.