Tooleux

JWE Decrypt

JWE (2)

Decrypt a compact JWE string back to plaintext.

Runs in your browser. Nothing leaves your device.
Decrypt JSON Web Encryption (JWE) compact strings in your browser. Supports RSA-OAEP, A256KW, and direct modes. Free, offline, runs client-side. Read more Show less

What is JWE Decrypt?

JWE Decrypt reverses the encryption performed by JWE Encrypt. It reads a compact JWE string and uses the matching decryption key to recover the original plaintext.

JWE is defined in RFC 7516. It is the encryption counterpart to JWS (signing). Where JWS ensures integrity, JWE ensures confidentiality.

How to use

Paste the compact JWE string, paste the appropriate decryption key, and press Decrypt.

For RSA-based JWEs (alg = RSA-OAEP or RSA-OAEP-256), use the private key PEM (PKCS#8, BEGIN PRIVATE KEY). For symmetric JWEs (alg = A256KW, A128KW, or dir), use the same shared secret that was used to encrypt.

Supported algorithms

Key management: RSA-OAEP, RSA-OAEP-256, A256KW, A128KW, dir.

Content encryption: A256GCM, A192GCM, A128GCM, A128CBC-HS256.

The tool reads the algorithms from the JWE header, so you do not need to specify them - the key you provide just needs to match.

Why does decryption fail?

Four common causes:

Wrong key. For RSA, the private key must be the pair of the public key that was used to encrypt. For symmetric, the shared secret must match exactly.

Wrong key format. RSA-OAEP requires a PEM private key in PKCS#8 format (BEGIN PRIVATE KEY). If your key is in PKCS#1 format (BEGIN RSA PRIVATE KEY), convert it with openssl pkcs8 -topk8 -nocrypt.

Tampered JWE. Any modification to the ciphertext, IV, or tag will cause authentication failure. This is by design - AEAD algorithms detect tampering.

Not a JWE. If the string has 3 parts instead of 5, it is a JWS (signed) not a JWE (encrypted). Use the JWT Decoder for JWS.

FAQ

Can I decrypt a JWE without the key?

No. JWE uses modern ciphers (AES-GCM or AES-CBC-HMAC), which have no practical attacks that would reveal the plaintext without the key. This is the whole point.

Is the plaintext still in the JWE somewhere?

No. The plaintext is encrypted with AES. The "ciphertext" section of the JWE contains only the encrypted bytes - there is no way to recover the plaintext without the key.

How do I know if I have the right key?

The AEAD tag verifies this. If you have the wrong key, decryption fails immediately with an authentication error. You will not get garbage plaintext - you will get an error.

Can I use the public key to decrypt?

No. Public keys can only encrypt (or verify, in signing). Only the private key can decrypt.

Does the JWE format hide the algorithms?

The header is Base64URL-encoded but not encrypted. Anyone can read the alg and enc fields. This is intentional - the recipient needs to know which algorithms to use before they have the key.

Is it safe to paste ciphertext into a browser tool?

This tool runs entirely client-side. Nothing is uploaded. Verify by opening your browser's Network tab and confirming no requests are sent after page load.

Command line equivalent
# Node with jose
npm i jose
node --input-type=module -e '
import { compactDecrypt, importPKCS8 } from "jose";
import fs from "fs";
const pem = fs.readFileSync("private.pem", "utf8");
const key = await importPKCS8(pem, "RSA-OAEP-256");
const jwe = "eyJhbGciOi...";  // your compact JWE
const { plaintext, protectedHeader } = await compactDecrypt(jwe, key);
console.log(new TextDecoder().decode(plaintext));
console.log(protectedHeader);
'

# Python with jwcrypto
pip install jwcrypto
python3 -c '
from jwcrypto import jwe, jwk
key = jwk.JWK.from_pem(open("private.pem","rb").read())
token = jwe.JWE()
token.deserialize("your.jwe.here", key=key)
print(token.payload.decode())
'

# Go with go-jose
# See https://github.com/go-jose/go-jose
Loads a test value into the form
Compact JWE
Plaintext