JWE

Keys and Certificates

Online JWE Decoder, Encryptor and Decryptor

Inspect JSON Web Encryption compact tokens and work with their protected header, encrypted key, initialization vector, ciphertext and authentication tag. The tool supports debugging encrypted tokens with compatible PEM keys, JWK data and selected PFX/P12 containers.

JWE protects confidentiality, while JWS and signed JWT workflows focus on integrity and authenticity. Successful decryption requires a key and algorithms compatible with the token header.

JWE Compact Serialization

A compact JWE has five parts separated by dots: Protected Header, Encrypted Key, Initialization Vector, Ciphertext and Authentication Tag. The header can be decoded as JSON; the other parts remain encoded because they depend on the keys and algorithm used for encryption.

Encryption and decryption use algorithms supported by the WebCrypto API through the JOSE library. The header defines the alg and enc combination; for PEM public/private keys, the most common flows are RSA-OAEP and ECDH-ES. Symmetric algorithms such as dir, AES-KW, AES-GCM-KW and PBES2 depend on a compatible secret/JWK.

algAlgorithm used to protect the Content Encryption Key (CEK).
encAlgorithm used to encrypt the payload.
kidIdentifier of the key used for encryption.
typType of the token or JOSE object.
ctyType of the inner content, for example JWT in nested tokens.
zipCompression applied before encryption, usually DEF.
algRSA-OAEP, RSA-OAEP-256, RSA-OAEP-384, RSA-OAEP-512, ECDH-ES, ECDH-ES+A128KW, ECDH-ES+A192KW, ECDH-ES+A256KW, dir, A128KW, A192KW, A256KW, A128GCMKW, A192GCMKW, A256GCMKW, PBES2-HS256+A128KW, PBES2-HS384+A192KW, PBES2-HS512+A256KW
encA128GCM, A192GCM, A256GCM, A128CBC-HS256, A192CBC-HS384, A256CBC-HS512