JWT Token Decoder & Header Inspector
Decode Base64URL-encoded JSON Web Tokens directly in browser memory. 100% private with zero network requests.
⚠️ 5 Fatal Traps in JSON Web Tokens (JWT) & Auth Architecture
💥 1. The "alg: none" Algorithm Downgrade Vulnerability
In early JWT specs, "alg": "none" was supported for unauthenticated debugging. Attackers can forge arbitrary claims (e.g. {"admin": true}), set "alg": "none" in the header, strip the cryptographic signature, and submit the token. Naive verification libraries accept the forged payload as authentic unless explicitly configured to reject none.
⚖️ 2. Confusing Decoding with Cryptographic Verification (Base64 is NOT Encryption)
Standard JWTs are JWS (JSON Web Signatures), meaning payload data is merely Base64URL-encoded, not encrypted. Anyone who intercepts a token can read every claim. Furthermore, decoding claims on the client or API gateway without executing asymmetric RSA/ECDSA public-key or HMAC signature verification opens authorization bypass.
🛡️ 3. Storing Sensitive PII or Secrets in JWT Claims
Embedding passwords, Social Security numbers, internal system secrets, or detailed customer data in JWT claims creates severe compliance violations (GDPR/HIPAA). JWTs travel in HTTP headers across logs, CDNs, proxies, and browser developer tools. Keep tokens stateless with only non-sensitive subject IDs and scope identifiers.
🔍 4. The Token Revocation Impossibility & Long-Lived Expiration ('exp')
Because JWT verification is stateless, an issued token CANNOT be easily invalidated before its exp timestamp without querying a centralized Redis blacklist (which destroys the benefit of stateless auth). Issuing access tokens with 7-day or 30-day lifespans means compromised tokens remain valid even after the user changes their password or is terminated. Keep access tokens under 15 minutes.
🚀 5. Storing JWTs in 'localStorage' (Total XSS Exposure)
Storing authentication JWTs in window.localStorage or sessionStorage makes them accessible to ANY JavaScript code running on the page. A single compromised third-party analytics script or NPM dependency can exfiltrate all tokens. Secure session tokens should be delivered in httpOnly, Secure, SameSite=Strict cookies.