JWT Tokenlerini Çözme ve Claimleri Güvenli İnceleme
Quick Answer
JWT çözmek için: token'i JWT Decoder'a yapıştırın ve header ve payload anında formatlı JSON olarak görünür. Araç Base64URL parçalarını yerel olarak çözer —token tarayıcınızı asla terk etmez. Unutmayın: çözme sadece içeriği gösterir; signature doğrulamaz.
Introduction
JWT (JSON Web Token), authentication ve bilgi değişimi için kullanılan kompakt, URL-safe token formatıdır. JWT noktalarla ayrılmış üç parçaya sahiptir: header.payload.signature. Header algoritmayı belirtir, payload claim'leri (user ID, roles, expiration) içerir ve signature token değiştirilmediğini kanıtlar. Çözme, debugging için içeriği incelemenizi sağlar —ama çözme authenticity doğrulamaz.
Step by Step
-
Open the JWT Decoder tool
Go to the JWT Decoder tool page. The tool accepts any JWT string (three Base64URL-encoded parts separated by dots).
-
Paste your JWT token
Paste the JWT into the input field. A typical JWT looks like: eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ1c2VyMSJ9.signature. The tool auto-detects the three parts.
-
Review the decoded header
The tool Base64URL-decodes the first part and displays it as JSON. The header typically contains 'alg' (algorithm, e.g., HS256) and 'typ' (type, usually 'JWT').
-
Review the decoded payload (claims)
The tool decodes the second part and displays the claims as formatted JSON. Common claims include 'sub' (subject/user ID), 'iat' (issued at), 'exp' (expiration), and 'role' (user role).
-
Check the signature (third part)
The tool shows the signature part. Note: decoding does NOT verify the signature. To verify, you need the signing key and a verification library. Never trust a JWT's claims without verifying the signature server-side.
Examples
Decode a simple JWT
Input: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyMSIsIm5hbWUiOiJBbGljZSIsImlhdCI6MTY5MzUyNjQwMH0.signature
Output: Header: {"alg":"HS256","typ":"JWT"}
Payload: {"sub":"user1","name":"Alice","iat":1693526400}
JWT with expiration claim
Input: eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTY5MzYxMjgwMH0.sig
Output: Header: {"alg":"HS256"}
Payload: {"sub":"admin","exp":1693612800}
Common Problems
- Confusing decode with verify —decoding a JWT only reads its contents; it does NOT prove the token is authentic. Always verify the signature server-side with the signing key.
- Trusting expired tokens —check the 'exp' claim and reject expired tokens. The 'exp' value is a Unix timestamp in seconds.
- Base64 vs Base64URL —JWT uses Base64URL encoding (no padding, - and _ instead of + and /). A standard Base64 decoder will fail on JWT parts.
- Sensitive data in payload —JWT payloads are readable by anyone who has the token. Do not store passwords, credit card numbers, or other secrets in the payload.
Tips
- Always verify the JWT signature server-side before trusting any claims —decoding alone is not authentication.
- Check the 'exp' (expiration) and 'nbf' (not before) claims to ensure the token is valid for the current time.
- Use short-lived tokens (15-60 minutes) with refresh tokens for long sessions —minimizes damage if a token is leaked.
- Use our JWT Decoder for safe, local debugging —your token never leaves your browser.