JWT Decode — Reference
Inspect a token’s encoded header and payload without establishing trust.
Inspect a token’s encoded header and payload without establishing trust.
Before you begin
Section titled “Before you begin”- A Server Connect action. Test security behavior with an isolated test account or test-only token/key, not production credentials.
JWT Decode
Section titled “JWT Decode”Inspect a token’s encoded header and payload without establishing trust.
Settings
Section titled “Settings”| Setting | Meaning and example |
|---|---|
| Name | Names the decoded result in the action scope. |
| Token | The compact JWT string to decode. It contains dot-separated encoded parts, not an encrypted document. |
Verification example
Section titled “Verification example”Decode a test token and inspect result.header, result.payload and result.signature. Change the encoded payload without producing a new signature and decode again: the modified claims can still be readable. Pass the token to Verify before treating claims as trusted.
Behavior and limits
Section titled “Behavior and limits”Decode does not verify the signature, expiration or intended audience. Never use decoded role, user id or permissions directly to authorize a request. Malformed tokens may return null or fail differently across runtimes.
Use the complete authentication flow
Section titled “Use the complete authentication flow”Use the security and login guides for the surrounding provider, form, session and server-access configuration.
Check your result
Section titled “Check your result”You can configure the documented fields and distinguish a successful result from the failure or limitation described here.