الترميز
JWT Encoder/Decoder
ترميز وفك ترميز رموز JWT — الترويسة (Header)، الحمولة (Payload)، توقيع HMAC، والحقول القياسية.
الأمثلة الموقّعة (جميعها ما عدا none) تتطلب HTTPS — الصفحة مفتوحة حاليًا بدون HTTPS.
بالنسبة لـ RS/PS/ES، يتم إنشاء المفتاح تلقائيًا وبشكل مؤقت — لأغراض العرض فقط، ولا يمكن إعادة استخدامه.
الأمثلة الموقّعة (جميعها ما عدا none) تتطلب HTTPS — الصفحة مفتوحة حاليًا بدون HTTPS.
Claims
A JWT (JSON Web Token) is a compact format for transmitting signed data, made of three dot-separated parts: a header, a payload, and a signature. This tool decodes any JWT and shows all three parts, and can also build a new token signed with HMAC.
Decoding does not verify the signature — reading a token's contents needs no secret key. Verifying the signature only matters when you need to trust the token as genuine.
How to use it
- Decode: paste a JWT and the tool splits it into header, payload, and signature, highlighting standard claims like exp, iat, and sub.
- Encode: fill in the header and payload, provide a secret, and get a signed HMAC token (HS256/HS384/HS512) back.
- Check expiry: the exp claim is shown as a normal date, so you can immediately tell if a token has expired.
Common uses
- Debugging authentication issues by inspecting exactly what a request's token contains.
- Checking which claims (roles, permissions, expiry) your backend issues.
- Generating a test token for local development without running an auth server.
Things to keep in mind
A JWT is not encrypted, only Base64URL-encoded — anyone can read the payload. Never put passwords or other secrets in it.
The signature protects against tampering, not against being read. For confidentiality you need extra encryption (JWE) or an HTTPS transport.
مقالة عن هذه الأداة: JWT: بنية الرمز وماذا يعني "فك ترميز" JWT
الأسئلة الشائعة
هل فك ترميز JWT يثبت أنه صادر من جهة موثوقة؟
لا. فك الترميز بدون إدخال المفتاح السري يعرض فقط محتوى الـ Header وClaims داخل الـ Payload، لكنه لا يتحقق من صحة التوقيع. لإثبات أن الرمز أصيل ولم يُعدَّل يجب التحقق من التوقيع باستخدام المفتاح الصحيح.
ما الفرق بين exp وnbf وiat في الـ Claims؟
exp هو تاريخ انتهاء صلاحية الرمز، وnbf يحدد أقرب وقت يصبح فيه الرمز صالحًا للاستخدام، أما iat فهو وقت إصدار الرمز نفسه. جميعها طوابع زمنية بصيغة Unix.
هل المفتاح السري الذي أدخله لإنشاء أو التحقق من التوقيع يُرسَل لأي خادم؟
لا، كل عمليات الترميز وفك الترميز وحساب التوقيع تتم محليًا في متصفحك عبر Web Crypto API، ولا يغادر المفتاح أو الرمز جهازك أبدًا.
ما هو هجوم تبديل الخوارزمية إلى "none"؟
إذا وثق الخادم الخلفي بسذاجة بحقل alg الوارد في ترويسة الرمز، يستطيع المهاجم استبداله بـ none وإزالة التوقيع — فيجتاز رمز يحمل بيانات عشوائية عملية التحقق. تفرض المكتبات الموثوقة تحديد الخوارزمية المتوقعة صراحةً عند التحقق.
لماذا لا يُنصح بتخزين JWT في localStorage للجلسات الحساسة؟
يمكن لأي كود JavaScript يعمل على الصفحة الوصول إلى localStorage، لذا فهو عرضة لهجمات XSS — إذ يستطيع سكربت خبيث سرقة الرمز. للرموز الخاصة بالجلسات، يُفضَّل استخدام cookies من نوع httpOnly، غير القابلة للوصول من JavaScript.