Lukis' Space

← Tools

JWT decoder

Read a JSON Web Token's header and claims, with every timestamp as a date. Decoded right here; the token is never sent or stored.

Runs entirely in your browser. Nothing you enter here is sent to the server.

A live token works like a password

Until it expires, anyone who has a copy can use it as whoever it was issued to. This page decodes it right here: it is never sent, never stored and never put in the URL, and closing the tab forgets it.

A leading Bearer (or the whole Authorization: header) and stray whitespace are ignored.

What a JWT is, and why decoding it proves nothing

A JSON Web Token is three pieces of base64url joined by dots: a header saying how it is signed, a payload of claims, and a signature over the first two. The first two are only encoded, not encrypted, so anyone holding the token can read them without a key. That is all this page does. Never put anything in a claim you would not show the person holding the token.

iss, sub, aud
Who issued it, who it is about, and who it is meant for. A server should refuse a token whose aud is not itself.
exp, nbf, iat
Expiry, not-before and issued-at, in whole seconds since 1970 (UTC). Each is shown as a date in UTC and in your timezone.
jti
A unique ID, so a server can refuse the same token twice.

The signature is not checked

Checking it needs the issuer's key, and this page does not ask for one. The header's own alg must never decide how a token is checked: the verifier has to know which algorithm and key to expect. Libraries that trusted alg accepted "none", or a public RSA key used as an HMAC secret, and so accepted forgeries. A jku or x5u URL is shown but never fetched.

Encrypted tokens

A token with five parts is a JWE: the claims are encrypted to the recipient and cannot be read without their key. Its header is still plain base64url, so that part is shown.

The same thing offline

If a token is too sensitive for any web page, this is the payload in a terminal:

cut -d. -f2 <<< "$TOKEN" | tr '_-' '/+' | base64 -d

Other tools

  • Code scanner — Read QR codes and barcodes with your camera or from an image. Every format ZXing knows.
  • Code generator — Make a QR code, Data Matrix, Aztec, PDF417 or a linear barcode and download it.
  • Link inspector — See where a link really goes before you open or shorten it: the real host, lookalike letters, hidden redirects and tracking parameters.
  • Base converter — Encode and decode between text and Base2 through Base85, or convert integers between any two bases.
  • Hash generator — MD5, SHA family, CRC32 and MySQL5 over text or a file. The file is read in your browser.
  • SSH key fingerprint — SHA256 and MD5 fingerprints, key type and size, and SSHFP records for a public key. Private keys are refused unread.
  • Password generator — Random passwords from a CSPRNG, with the character classes you pick.
  • TOTP generator — Turn a TOTP secret or otpauth:// link into the current code. The secret stays on your device.
  • Timestamp converter — Unix time to a calendar date and back, in every format at once. Live clock included.
  • Subnet calculator — IPv4 and IPv6: network, range, host count, masks and reverse-DNS pointers.
  • Image resizer — Resize and convert an image without it ever leaving your browser. Re-encoding drops EXIF and GPS.
  • IP info — Your public IPv4 and IPv6, as this server sees them.
  • PHP obfuscator — Wrap PHP so it self-decodes at runtime. Runs on the server; the code is never stored.