การเข้ารหัส
JWT Encoder/Decoder
เข้ารหัสและถอดรหัสโทเคน JWT — header, payload, ลายเซ็น HMAC และฟิลด์มาตรฐาน
ตัวอย่างที่มีลายเซ็น (ทั้งหมดยกเว้น none) ต้องใช้ HTTPS — ขณะนี้หน้านี้เปิดโดยไม่มี HTTPS
สำหรับ RS/PS/ES คีย์จะถูกสร้างขึ้นอัตโนมัติและใช้ชั่วคราว — เพื่อการสาธิตเท่านั้น ใช้ซ้ำไม่ได้
ตัวอย่างที่มีลายเซ็น (ทั้งหมดยกเว้น none) ต้องใช้ HTTPS — ขณะนี้หน้านี้เปิดโดยไม่มี HTTPS
Claims
A JWT (JSON Web Token) is a compact format for transmitting signed data, made of three dot-separated parts: a header, a payload, and a signature. This tool decodes any JWT and shows all three parts, and can also build a new token signed with HMAC.
Decoding does not verify the signature — reading a token's contents needs no secret key. Verifying the signature only matters when you need to trust the token as genuine.
How to use it
- Decode: paste a JWT and the tool splits it into header, payload, and signature, highlighting standard claims like exp, iat, and sub.
- Encode: fill in the header and payload, provide a secret, and get a signed HMAC token (HS256/HS384/HS512) back.
- Check expiry: the exp claim is shown as a normal date, so you can immediately tell if a token has expired.
Common uses
- Debugging authentication issues by inspecting exactly what a request's token contains.
- Checking which claims (roles, permissions, expiry) your backend issues.
- Generating a test token for local development without running an auth server.
Things to keep in mind
A JWT is not encrypted, only Base64URL-encoded — anyone can read the payload. Never put passwords or other secrets in it.
The signature protects against tampering, not against being read. For confidentiality you need extra encryption (JWE) or an HTTPS transport.
บทความเกี่ยวกับเครื่องมือนี้: JWT: โครงสร้างโทเคนและความหมายของการ "ถอดรหัส" JWT
คำถามที่พบบ่อย
การถอดรหัส JWT ยืนยันลายเซ็นด้วยหรือไม่?
ไม่ การถอดรหัสเป็นเพียงการทำ base64url-decode ส่วนหัวและ payload เพื่อให้อ่าน claim ได้เท่านั้น ไม่ได้พิสูจน์ว่าโทเคนนั้นแท้จริง หากต้องการยืนยันลายเซ็นจริง ๆ ต้องป้อนคีย์ลับหรือคีย์สาธารณะที่ถูกต้องที่นี่
การวาง JWT จริงลงในเครื่องมือนี้ปลอดภัยหรือไม่?
การถอดรหัสและการเซ็นทั้งหมดทำในเบราว์เซอร์ของคุณ โทเคนและคีย์ลับใด ๆ ที่ป้อนจะไม่ถูกส่งไปยังเซิร์ฟเวอร์ อย่างไรก็ตาม ควรระมัดระวังกับโทเคนจากระบบจริง เพราะใครก็ตามที่เห็น JWT ที่ถอดรหัสแล้วสามารถอ่าน claim ได้
ทำไมโทเคนของฉันแสดงว่าหมดอายุทั้งที่ยังใช้งานได้ในแอป?
ตัวบ่งชี้หมดอายุ/ใช้ได้ที่นี่เปรียบเทียบ claim exp กับเวลาปัจจุบันเท่านั้น ไม่ได้ตรวจสอบค่าความคลาดเคลื่อนของนาฬิกาหรือกฎการตรวจสอบอื่น ๆ ที่เซิร์ฟเวอร์หรือไลบรารีของคุณอาจใช้
การโจมตีด้วยการสวมรอยอัลกอริทึมเป็น "none" คืออะไร?
หากเบิร์กเอนด์เชื่อฟิลด์ alg จาก header ของโทเค็นอย่างไร้เดียงสา ผู้โจมตีสามารถแทนที่ด้วย none ตัดลายเซ็นทิ้ง แล้วโทเค็นที่มีข้อมูลใด ๆ ก็จะผ่านการตรวจสอบ ไลบรารีที่เชื่อถือได้จะบังคับให้ระบุอัลกอริทึมที่คาดหวังไว้อย่างชัดเจนตอนตรวจสอบ
ทำไมไม่ควรเก็บ JWT ไว้ใน localStorage สำหรับเซสชันที่ละเอียดอ่อน?
localStorage เข้าถึงได้จากโค้ด JavaScript ใด ๆ บนหน้าเว็บ จึงเสี่ยงต่อ XSS — สคริปต์อันตรายสามารถขโมยโทเค็นได้ สำหรับโทเค็นเซสชันควรใช้ httpOnly-cookie ซึ่ง JavaScript เข้าถึงไม่ได้แทน จะปลอดภัยกว่า