انتقل إلى المحتوى
خط الاستجابة الطارئة 24/7
ar
الخدمات
الحلول
الأبحاث
الشركة
الأدواتمركز الثقة

JWT Decoder

JWTs carry sessions and permissions in modern applications; misconfigured, they open the door to account takeover. This tool shows what's inside a token and whether it contains risky settings.

هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.

The token and secret never leave your browser.

Queries are not stored. The tools use public information only; client-side tools never send your data anywhere.

What this tool checks

  • Header: algorithm (alg), type and key ID (kid)
  • Payload: every claim
  • exp, iat, nbf dates and time remaining
  • Risky settings such as “alg: none” and tokens without expiry
  • HMAC (HS256/384/512) signature verification

How to use it

  1. 01

    Paste the token (it starts with eyJ…).

  2. 02

    Header and payload decode instantly.

  3. 03

    For HS* tokens, enter the secret to verify the signature.

Technical details

Decoding is not verifying

A JWT's header and payload are only Base64URL-encoded; anyone can read them. Security depends on the server verifying the signature with the right key and algorithm.

Common mistakes

Accepting “alg: none”, trusting the algorithm from the token itself, weak HMAC secrets, long-lived tokens without exp and sensitive data in the payload are the findings we see most.

Privacy

The token and secret stay in your browser; verification runs locally with the Web Crypto API. Still, avoid sharing production tokens.

Frequently asked questions

Is the payload encrypted?

No. Standard JWT (JWS) content is only encoded. Use JWE for data that must stay secret, or keep it out of the token.

Can I verify RS256 or ES256 tokens?

This tool currently verifies HMAC (HS*) signatures only. Asymmetric signatures need the issuer's public key (JWKS).

How long should a token live?

Short lifetimes for access tokens — minutes — plus separate, revocable refresh tokens are recommended.

Why is “alg: none” dangerous?

It means an unsigned token. If the server accepts it, anyone can mint tokens for any user or role.