Tools / JWT Decoder
JWT Decoder
Paste a JWT token to instantly decode its three parts: the algorithm header, the claims payload, and the base64url-encoded signature. The token structure is color-coded so you can see exactly where each section begins and ends.
Try an example
Paste a JWT token above to decode its header and payload.
JWTs in CTF web challenges
A JSON Web Token is a compact, URL-safe way to transmit claims between parties. It consists of three base64url-encoded parts separated by dots: header.payload.signature. The header specifies the signing algorithm (e.g. HS256), the payload carries the actual claims, and the signature verifies integrity.
Common CTF vulnerabilities involve JWTs:
- Weak secret - if the HMAC secret is short or guessable, forge a new token with elevated privileges.
- Algorithm confusion - changing
algfromRS256toHS256and signing with the public key as the HMAC secret. - None algorithm - some libraries accept
"alg": "none"and skip signature verification entirely.
Challenges solved with this tool: picoCTF 2023 - Java Code Analysis!?!.
The header and payload parts of a JWT are just Base64url-encoded JSON - there is no encryption by default. This means the payload is readable by anyone who holds the token, even without the secret key. Sensitive claims like role, admin, or userId are fully visible. In CTF challenges, decoding the payload often reveals the exact field you need to modify to escalate privileges.
To forge a modified JWT in a CTF, you typically need to re-sign the tampered payload with the correct algorithm and secret. If the server uses the none algorithm vulnerability, you can simply remove the signature and change alg to none in the header. For HMAC-signed tokens with a guessable secret (e.g., secret or password), crack the secret with tools like jwt-cracker or hashcat mode 16500.
Standard JWT claims to look for in the payload include sub (subject/user ID), exp (expiration timestamp), and iat (issued-at timestamp). An expired token (where exp is in the past) may still be accepted by a misconfigured server - this is worth testing when the challenge involves session management. Use the Timestamp Converter to convert iat and exp values to human-readable dates.
Challenges where it helps
- Credential StuffingpicoCTF 2026 · Web Exploitation · Medium
- Fool the LockoutpicoCTF 2026 · Web Exploitation · Medium
- No FApicoCTF 2026 · Web Exploitation · Medium
- head-dumppicoCTF 2025 · Web Exploitation · Easy
- IntroToBurppicoCTF 2024 · Web Exploitation · Easy
- Java Code Analysis!?!picoCTF 2023 · Web Exploitation · Medium
- GET aHEADpicoCTF 2021 · Web Exploitation · Easy
- JaWT ScratchpadpicoCTF 2019 · Web Exploitation · Medium
- logonpicoCTF 2019 · Web Exploitation · Easy
- picobrowserpicoCTF 2019 · Web Exploitation · Medium
- Crack the Gate 1picoMini by CMU-Africa · Web Exploitation · Easy
- Crack the Gate 2picoMini by CMU-Africa · Web Exploitation · Medium
Browse the full challenge library for 1 more.
Guides that use this tool
- PHP Type Juggling for CTF: Magic Hashes, Array Tricks, and What PHP 8 BrokeLoose comparison bugs in PHP, from 0e magic hashes to passing arrays into strcmp, plus which classic tricks PHP 8 killed and which ones still work in 2026.
- sqlmap for CTF: Every Flag That Matters, and What to Do When It Finds NothingA practical sqlmap workflow for CTF: request files, level and risk, technique selection, tamper scripts, second-order injection, and the failure checklist.
- WebAssembly Reversing for CTF: Reading WAT and Recovering Flags from .wasmFind the .wasm a page loads, disassemble it to WAT with wabt, read the stack machine, pull constants out of the data section, and debug it live in DevTools.
- HTTP for CTF: Requests, Headers, Status Codes, and DevToolsHTTP fundamentals for web CTF: read a request and response, forge headers with curl, use the DevTools Network tab, and solve the header and redirect challenge class.
- JavaScript Deobfuscation for CTF: Hook the Sink, Not the SourceDeobfuscate CTF JavaScript by hooking eval, Function, and atob instead of reading minified code. Includes WebAssembly reversing and a DevTools workflow.
- The picoCTF Web Exploitation Roadmap: Recon to RCEWeb exploitation roadmap: how to learn web hacking in order, a difficulty-tiered path classifying every bug by where your input lands, with technique guides.
Tools that pair with this one
- Base64 & Base32 DecoderDecode Base64 and Base32 strings with auto-detection. Multi-layer mode unwraps nested encodings automatically.
- Flask Session DecoderDecode Flask / itsdangerous session cookies. Splits payload, decompresses zlib, parses JSON, and verifies the HMAC signature when given the secret.
- Hash IdentifierIdentify unknown hash types by length and prefix. Covers MD5, SHA-1, SHA-256, SHA-512, bcrypt, NTLM, and more.
- Timestamp ConverterConvert Unix timestamps (seconds or milliseconds), hex timestamps, and date strings to every common format.
Or browse all 40 CTF tools.