Skip to content
🔧

JWT 디코더

인코딩 및 암호화 · 무료 온라인 도구

JWT 토큰을 디코딩하고 헤더와 페이로드를 검사.

CoderNewbie 팀
176 문자

세 부분 구조

JWT는 header.payload.signature 구조이며, 각각 base64url로 인코딩됩니다. 이 도구는 세 부분 모두를 분할하고 디코딩합니다.

시간 클레임

표준 클레임인 exp, iat, nbf를 유효성 상태와 함께 사람이 읽을 수 있는 날짜로 렌더링합니다.

디코딩 전용

이 도구는 토큰을 디코딩하고 표시만 합니다 — 서명을 검증하지 않습니다. 검증 없이 클레임을 신뢰하지 마세요.

JWT 디코더 사용 방법

  1. 1Enter or paste your data into the input field.
  2. 2Select the desired encoding, hashing, or encryption options.
  3. 3Click the action button to process your data.
  4. 4Copy the result from the output field.

주요 기능

  • 100% 무료 — 가입, 구독, 광고 없음
  • 브라우저에서만 실행 — 데이터는 기기를 떠나지 않습니다
  • 빠르고 가벼움 — 즉시 결과 확인
  • 크로스 플랫폼 — 데스크톱, 태블릿, 모바일 지원

JWT 디코더 소개

JSON Web Token (JWT), defined by RFC 7519, is a compact, URL-safe token format for securely transmitting claims between parties. A JWT consists of three Base64URL-encoded parts separated by dots: Header.Payload.Signature. It is widely used for API authentication, OAuth 2.0, and SSO.

JWT 디코더 작동 원리

The Header specifies the signing algorithm (e.g., HS256, RS256). The Payload contains claims (registered, public, private) — statements about an entity. The Signature is computed over the encoded Header and Payload using the algorithm and a secret/private key. To verify, recompute the signature and compare.

주요 활용 사례

  • API authentication — bearer tokens in Authorization headers
  • OAuth 2.0 — access tokens and ID tokens
  • SSO — share identity across multiple services
  • Stateless sessions — store user info without server-side sessions

JWT vs Session Cookies

Sessions store state server-side; JWTs are stateless and self-contained. JWTs scale better (no session store) but are harder to revoke before expiry. Sessions are more secure for sensitive apps (can revoke instantly); JWTs suit distributed/microservice architectures. Always use HTTPS for both.

보안 및 개인정보

This tool decodes JWTs locally in your browser — your token never leaves your device. IMPORTANT: Decoding a JWT only reads its contents; it does NOT verify the signature. Never trust JWT claims without server-side signature verification. JWTs are visible to anyone who intercepts them — use HTTPS.

기술 세부 정보

Standard: RFC 7519. Structure: Base64URL(Header).Base64URL(Payload).Base64URL(Signature). Header: alg (HS256/RS256/ES256/none), typ. Registered claims: iss (issuer), sub (subject), aud (audience), exp (expiry), nbf (not before), iat (issued at), jti (JWT ID). Signature: HMAC(SHA-256) for HS256, RSA for RS256. 'alg: none' tokens must always be rejected.

자주 묻는 질문

Is decoding a JWT the same as verifying it?

No. Decoding reads the payload; verification checks the signature cryptographically. Anyone can decode a JWT; only the server with the secret can verify it. Never trust unverified JWT claims.

What is the 'alg: none' vulnerability?

If a server accepts 'alg: none' tokens, attackers can forge tokens without a signature. Always reject 'none' algorithm and use a hardcoded allowed-algorithms list.

How long should a JWT live?

Access tokens: 15-60 minutes. Refresh tokens: days to weeks. Short-lived access tokens limit damage if leaked. Use refresh tokens to maintain sessions.

관련 도구