Skip to content

JWT Decode — Reference

Reference · Advanced · Server Connect

Inspect a token’s encoded header and payload without establishing trust.

Inspect a token’s encoded header and payload without establishing trust.

  • A Server Connect action. Test security behavior with an isolated test account or test-only token/key, not production credentials.

Inspect a token’s encoded header and payload without establishing trust.

Setting Meaning and example
NameNames the decoded result in the action scope.
TokenThe compact JWT string to decode. It contains dot-separated encoded parts, not an encrypted document.

Decode a test token and inspect result.header, result.payload and result.signature. Change the encoded payload without producing a new signature and decode again: the modified claims can still be readable. Pass the token to Verify before treating claims as trusted.

Decode does not verify the signature, expiration or intended audience. Never use decoded role, user id or permissions directly to authorize a request. Malformed tokens may return null or fail differently across runtimes.

Use the security and login guides for the surrounding provider, form, session and server-access configuration.

You can configure the documented fields and distinguish a successful result from the failure or limitation described here.