API Management Versions 7.5.X And 7.6.X Reached End Of Support In November 2020. Please Contact Axway Support To Discuss Which Options Are Available To You.

JWT decrypt filter


You can use the JWT Decrypt filter to decrypt encrypted JWTs.

Upon successful decryption, the filter removes all metadata, such as headers and encryption-specific information of the incoming encrypted JWT, and outputs the originally encrypted payload.

For example, when you decrypt the following JWE Payload:












The output is:

The true sign of intelligence is not knowledge but imagination.

Note   The JWT Decrypt filter automatically detects whether the input JWT is encrypted with symmetric or asymmetric key and automatically uses the corresponding settings. For example, you can configure decryption with symmetric key and certificate; however, the filter uses the former or latter depending on the type of JWE it receives as input.

General settings

Configure the following field on the JWT Decrypt window:


Enter an appropriate name for the filter to display in a policy.

Token location:

Enter the selector expression to obtain the JWT to be decrypted.

Decryption using key selection

Optionally, configure the following fields in the Key selection section:

X509 certificate:

Select the certificate from the certificate store that is used to decrypt the payload.

Selector expression:

Alternatively, enter a selector expression to retrieve the alias of the certificate in the certificate store.

Shared key selection details

Optionally, configure the following fields in the Shared key selection section:


Select if you do not want to decrypt tokens that are encrypted with shared keys.

Shared key:

Enter the shared key that is used to encrypt the payload. The key should be given as a base64-encoded byte array.

Selector expression:

Alternatively, enter a selector expression to obtain the shared key. The value returned by the selector should contain:

  • Byte array (possibly produced by a different filter)
  • Base64-encoded byte array


Related Links