JWE Token Decoder
Decode and analyze JWE (JSON Web Encryption) token structure. Inspect protected headers, algorithms, and key IDs without decrypting the payload.
Features
đ Header Inspection
- Decode protected header (alg, enc, kid)
- Display all header claims
- Identify token type and content type
- Detect compression algorithm
đ Structure Analysis
- Validate 5-part JWE format
- Show part sizes (header, key, IV, ciphertext, tag)
- Detect direct key agreement (empty encrypted key)
- Total token length summary
đ Algorithm Reference
- Human-readable algorithm descriptions
- Key management algorithm (alg) info
- Content encryption algorithm (enc) info
- Covers RSA-OAEP, AES-KW, ECDH-ES, GCM
JWE Reference Guide
JWE Compact Serialization
A JWE token in compact serialization consists of exactly 5 Base64url-encoded parts separated by dots:
BASE64URL(JWE Protected Header) . BASE64URL(JWE Encrypted Key) . BASE64URL(JWE Initialization Vector) . BASE64URL(JWE Ciphertext) . BASE64URL(JWE Authentication Tag)
Only the Protected Header is readable without the private key. The ciphertext (payload) remains encrypted.
JWE in practice
A JWE keeps its payload confidential, unlike a signed JWT whose payload anyone can read. You meet JWEs in some identity systems, open banking APIs and anywhere tokens carry sensitive data through the browser.
Tips and common pitfalls
- Only the protected header is readable without the key. It tells you the key management algorithm (
alg) and content encryption (enc). - A nested JWT is signed first and then encrypted. After decrypting, the plaintext is itself a JWS you must verify.
- Prefer modern algorithms such as
RSA-OAEP-256orECDH-ESwithA256GCM. AvoidRSA1_5, which has known weaknesses. - The
kidheader tells the receiver which private key to use for decryption.
More questions
Why does a JWE have five parts?
Header, encrypted key, initialization vector, ciphertext and authentication tag, each Base64URL-encoded and joined with dots.
Which libraries can decrypt JWEs?
Popular choices are jose for Node.js and browsers, Nimbus JOSE + JWT for Java and python-jose or joserfc for Python.