./prontouso.com
CÔNG CỤ LẬP TRÌNH

Giải Mã Token JWT

Giải mã chuỗi token JWT để xem cấu trúc Header và Payload dưới dạng JSON rõ ràng. Kiểm tra thời gian hết hạn (exp) và thời điểm phát hành (iat) mà không cần gửi token đi đâu.

Trạng thái công cụChạy trên trình duyệt của bạn
Xem trước

JWT token

Token decoded. Signature is not verified.

Kết quả

Expires
1/1/2050, 12:00:00 AM
Trạng thái
Not expired

Cách thức hoạt động

  1. Nhập dữ liệu của bạn

    Điền các giá trị cần thiết, dán văn bản hoặc tải lên tệp bạn muốn xử lý.

  2. Xem kết quả tức thì

    Hầu hết các công cụ cập nhật theo thời gian thực khi bạn nhập liệu; một số công cụ sử dụng một nút hành động duy nhất.

  3. Sử dụng kết quả

    Sao chép, tải xuống hoặc chia sẻ kết quả được tạo — bạn luôn có toàn quyền kiểm soát dữ liệu của mình.

Quyền riêng tư & xử lý dữ liệuChạy cục bộ 100% trên trình duyệt của bạn. Công cụ này không tải dữ liệu của bạn lên máy chủ.

Giải Mã Token JWT là gì?

Paste a JSON Web Token to inspect its header and payload claims without sending the token away from your browser.

TÌM HIỂU CÁCH HOẠT ĐỘNG CỦA CÔNG CỤ

How to decode a JWT

What this decoder shows

The tool decodes the Base64URL header and payload, formats the JSON, and checks whether a numeric exp claim is already expired.

Important limitation

Decoding is not verification. Anyone can decode a JWT; signature verification requires the correct secret or public key and is intentionally not performed here.

Claims to inspect

  • exp tells you when the token expires.
  • iss often identifies the issuer.
  • sub usually identifies the subject or user.

Token handling

Decoding a JWT is not the same as verifying its signature. Avoid using sensitive production tokens in examples, screenshots, or shared sessions.

Các Câu Hỏi Thường Gặp (FAQ)

Does this verify the JWT signature?

No. It only decodes header and payload so you can inspect claims safely.

Is it safe to paste a token here?

The tool runs locally, but you should still avoid pasting highly sensitive production tokens into any page you do not control.

What if my JWT has no exp claim?

The decoder still shows the payload, but it cannot tell whether the token is expired.

Does this verify the signature?

No. It decodes the header and payload and reads exp, but it does not verify the signature or trust the token.

Công Cụ Liên Quan