jwtDecode

Decodes a JWT and returns its payload claims as a struct WITHOUT verifying the signature. For inspection only — never trust decoded claims without jwtVerify(). This is the Lucee crypto-extension name; RustCFML does not provide the Adobe createSignedJWT/verifySignedJWT names. Only HMAC algorithms (HS256/HS384/HS512) are supported by the jwt* family.

jwtDecode(token) → returns struct

This function requires RustCFML.  Not supported on Lucee, Adobe ColdFusion, etc.

Argument Reference

token string
Required

The JWT to decode (three dot-separated base64url parts).

Examples
Sample code invoking the jwtDecode function

Decode a signed token without verifying it.

token = jwtSign({ sub: "alex", role: "admin" }, "my-secret");
claims = jwtDecode(token);
writeDump(claims.sub);

Expected Result: alex

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub