JWT Decode
Decode a JSON web token without verifying the signature.
Type
crypto.jwt.decodeFolder
basic/cryptoChannels
Any
Pipe
Value
Scope
Any
JWT Decode reads the token parts without checking the signature. Treat the result as untrusted. Use JWT Verify when the token must be authentic.
Configure
| Setting | Description |
|---|---|
| Token | Compact JWT (required) |
| Return additional info | Off: payload only. On: header, payload, and signature |
Handles
| Handle | Role |
|---|---|
| In (target) | Incoming connection |
| Out (source) | Continues after decoding |
| Error | Catchable failures: missing token (MISSING_VALUE) or not a JWT (JWT_MALFORMED) |
Connect Branch errors to Error to split those codes.
Pipe schema
The pipe is the payload object, or header + payload + signature when Return additional info is on.
Use case
- Inspect claims while debugging a flow.
- Read a
kidfrom the header so you can pick a key, then JWT Verify.