JWT & セキュリティガイド

Base64URLとJSON Web Token(JWT)の仕組み

JSON Web TokenがBase64URLエンコードを使用する理由を解説。ヘッダー・ペイロード・署名の3部構造、alg:none脆弱性、クレーム検証の手順。

JWTにおけるBase64URLの役割

A JSON Web Token (JWT) is a compact, URL-safe means of representing claims between two parties. To ensure JWT tokens can be safely transmitted inside HTTP headers, query parameters, or cookies without being modified or corrupted by web proxies, the token standard uses Base64URL encoding.

Standard Base64 contains + and / characters, which have special meanings in URLs. Base64URL replaces + with -, / with _, and strips trailing = padding.

JWTを構成する3つの要素

JWT Structure:

Header (Base64URL) . Payload (Base64URL) . Signature (Base64URL)

Example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIn0.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Base64エンコードは暗号化ではありません!

A common security misconception is assuming a JWT's contents are encrypted because they look scrambled. Base64URL is simple encoding, not encryption. Anyone who captures a JWT can decode and read its header and payload instantly using our JWT Decoder Tool or Base64 Guide. Never store sensitive passwords or unencrypted secrets in a JWT payload.

⚠️ Security Warning: Base64URL does not encrypt or obscure JWT data from unauthorized readers. Always encrypt sensitive tokens with JWE if confidentiality is required.