You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用HS256算法的JWT令牌可Base64解密是否正常及防护咨询

Is it normal that JWT Header/Payload can be decoded but Signature can't, and how to prevent payload from being decoded?

Hey there! This is totally normal behavior for JWTs—you haven’t made any mistakes here. Let me break it down for you:

Why Header/Payload are decodeable, but Signature isn’t

JWTs are structured into three parts separated by dots: [Header].[Payload].[Signature]

  • The Header and Payload are encoded using Base64Url (a URL-safe variant of Base64), not encrypted. This encoding is just for making the data easy to transmit over HTTP (since JSON can have characters that aren’t URL-friendly), not for keeping it secret. That’s why you can easily decode them to see the original content.
  • The Signature is a hash generated using your secret key (with the HS256 algorithm you’re using). It’s created by hashing the combined Base64Url-encoded Header and Payload, plus your secret. Since hashing is a one-way function (you can’t reverse it to get the original input), you can’t "decode" the Signature—its only purpose is to let the receiver verify that the Header and Payload haven’t been tampered with.

How to prevent your token content from being decoded

Since JWT’s default design doesn’t encrypt content, if you have sensitive data in the Header or Payload (like user PII, internal IDs, or confidential info), you need to add an extra layer of protection:

  • Use JWE (JSON Web Encryption):This is the official standard for encrypting JWT content. JWE takes the entire JWT (Header and Payload) and encrypts it, so even if someone intercepts the token, they can’t read the content without the decryption key. For HS256 users, you can pair it with symmetric encryption algorithms like AES-GCM to encrypt the payload.
  • Encrypt sensitive fields before adding them to the Payload:If you don’t want to implement full JWE, you can manually encrypt any sensitive data in your Payload using a symmetric encryption algorithm (like AES) before encoding it into the JWT. Even if someone decodes the Base64Url Payload, they’ll only get encrypted text that’s unreadable without your encryption key.

A quick reminder: JWT is designed primarily for authentication and integrity verification, not for secure data storage. Never put plaintext sensitive information in a JWT unless you’ve encrypted it first.

内容的提问来源于stack exchange,提问作者Luis Gonzalez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:15:20