F

JWT 解析器JWT Decoder

解码和验证JSON Web TokenDecode and validate JSON Web Tokens.

关于 JWT 解析器About JWT Decoder

JWT(JSON Web Token)是接口鉴权与单点登录的常见载体。本工具在本地解码 JWT 的 Header 与 Payload,展示算法、签发者、过期时间等声明,并将时间戳转为可读时间,是排查登录鉴权问题的顺手工具。JWT (JSON Web Token) is a common bearer for API authentication and single sign-on. This tool decodes a JWT’s Header and Payload locally, showing the algorithm, issuer, expiration and other claims with timestamps rendered as readable times — handy for debugging auth issues.

使用方法How to Use

  1. 粘贴完整的 Token(形如 xxx.yyy.zzz 的三段结构)。Paste the complete token (the three dot-separated parts).
  2. 工具自动解码并展示 Header 与 Payload 的 JSON 内容。The tool automatically decodes and displays the Header and Payload JSON.
  3. 查看 exp、iat 等时间声明,工具已将其转换为可读时间。Inspect claims such as exp and iat, already converted to readable times.
  4. 根据过期时间与声明内容判断 Token 是否有效。Judge whether the token is valid based on expiry and claim values.

常见问题FAQ

把 Token 粘贴到这里安全吗?Is it safe to paste my token here?

解码在浏览器本地完成,不会上传。另外要明白 JWT 的 Payload 只是 Base64 编码而非加密,任何人拿到都能读,因此其中本就不应存放敏感信息。Decoding happens locally and nothing is uploaded. Also remember a JWT Payload is Base64-encoded, not encrypted — anyone holding it can read it, so it should never contain sensitive data in the first place.

能验证签名吗?Can it verify the signature?

本工具专注于解码查看。签名验证需要密钥或公钥,且应在服务端完成;在浏览器里放密钥反而会造成泄露。This tool focuses on decoding. Signature verification needs the secret or public key and belongs on the server; putting keys in a browser would leak them.

为什么解码失败?Why does decoding fail?

常见原因是 Token 复制不完整(漏掉某一段或点号)、带了 Bearer 前缀或多余空白。请粘贴完整的三段式字符串。Common causes are an incomplete copy (a missing segment or dot), a Bearer prefix, or extra whitespace. Paste the full three-part string.

相关阅读Related Reading

相关工具Related Tools