Décodeur JWT
Encodage & Chiffrement · Outil en ligne gratuit
Décoder les jetons JWT et inspecter l'en-tête et la charge utile.
Structure en trois parties
Un JWT est header.payload.signature, chacun encodé en base64url. Cet outil sépare et décode les trois.
Claims temporels
Les claims standards exp, iat et nbf sont affichés en dates lisibles avec le statut de validité.
Décodage uniquement
Cet outil décode et affiche le token — il ne vérifie pas la signature. Ne faites jamais confiance aux claims sans vérifier d'abord.
Comment utiliser Décodeur JWT
- 1Enter or paste your data into the input field.
- 2Select the desired encoding, hashing, or encryption options.
- 3Click the action button to process your data.
- 4Copy the result from the output field.
Fonctionnalités
- ✓100% gratuit — sans inscription, sans abonnement, sans publicité
- ✓Fonctionne entièrement dans votre navigateur — vos données ne quittent jamais votre appareil
- ✓Rapide et léger — résultats instantanés
- ✓Multiplateforme — compatible ordinateur, tablette et mobile
Qu'est-ce que Décodeur JWT ?
JSON Web Token (JWT), defined by RFC 7519, is a compact, URL-safe token format for securely transmitting claims between parties. A JWT consists of three Base64URL-encoded parts separated by dots: Header.Payload.Signature. It is widely used for API authentication, OAuth 2.0, and SSO.
Comment fonctionne Décodeur JWT ?
The Header specifies the signing algorithm (e.g., HS256, RS256). The Payload contains claims (registered, public, private) — statements about an entity. The Signature is computed over the encoded Header and Payload using the algorithm and a secret/private key. To verify, recompute the signature and compare.
Cas d'usage courants
- ✓API authentication — bearer tokens in Authorization headers
- ✓OAuth 2.0 — access tokens and ID tokens
- ✓SSO — share identity across multiple services
- ✓Stateless sessions — store user info without server-side sessions
JWT vs Session Cookies
Sessions store state server-side; JWTs are stateless and self-contained. JWTs scale better (no session store) but are harder to revoke before expiry. Sessions are more secure for sensitive apps (can revoke instantly); JWTs suit distributed/microservice architectures. Always use HTTPS for both.
Sécurité et confidentialité
This tool decodes JWTs locally in your browser — your token never leaves your device. IMPORTANT: Decoding a JWT only reads its contents; it does NOT verify the signature. Never trust JWT claims without server-side signature verification. JWTs are visible to anyone who intercepts them — use HTTPS.
Détails techniques
Standard: RFC 7519. Structure: Base64URL(Header).Base64URL(Payload).Base64URL(Signature). Header: alg (HS256/RS256/ES256/none), typ. Registered claims: iss (issuer), sub (subject), aud (audience), exp (expiry), nbf (not before), iat (issued at), jti (JWT ID). Signature: HMAC(SHA-256) for HS256, RSA for RS256. 'alg: none' tokens must always be rejected.
Questions fréquentes
Is decoding a JWT the same as verifying it?
No. Decoding reads the payload; verification checks the signature cryptographically. Anyone can decode a JWT; only the server with the secret can verify it. Never trust unverified JWT claims.
What is the 'alg: none' vulnerability?
If a server accepts 'alg: none' tokens, attackers can forge tokens without a signature. Always reject 'none' algorithm and use a hardcoded allowed-algorithms list.
How long should a JWT live?
Access tokens: 15-60 minutes. Refresh tokens: days to weeks. Short-lived access tokens limit damage if leaked. Use refresh tokens to maintain sessions.
Outils associés
Générateur UUID / NanoID
Générer des UUID v4 et NanoID en lot.
Générateur de mots de passe
Générer des mots de passe aléatoires sécurisés.
Chiffrement AES
Chiffrer/déchiffrer en AES-GCM-256 avec dérivation de clé PBKDF2.
Outil RSA
Générer des paires de clés RSA-2048 et chiffrer/déchiffrer avec RSA-OAEP.
Hachage Bcrypt
Hacher les mots de passe avec bcrypt et vérifier par rapport aux hachages.
Générateur ULID
Générer des identifiants uniques universels triables lexicographiquement.
Générateur de Jetons
Générer des jetons aléatoires avec alphabet et longueur personnalisés.
Analyseur de Force de Mot de Passe
Analyser la force du mot de passe et estimer le temps de cracking.