{"id":2114,"date":"2026-04-06T10:47:18","date_gmt":"2026-04-06T10:47:18","guid":{"rendered":"https:\/\/primetoolhub.com\/?p=2114"},"modified":"2026-07-09T08:54:57","modified_gmt":"2026-07-09T08:54:57","slug":"free-offline-jwt-decoder-article","status":"publish","type":"post","link":"https:\/\/schoolict.net\/tools\/free-offline-jwt-decoder-article\/","title":{"rendered":"Free Offline JWT Decoder: How JSON Web Tokens Really Work"},"content":{"rendered":"<div class=\"pth-hero-section\">\n<div class=\"pth-hero-content\">\n<h2>How JSON Web Tokens Really Work: Structure, Signatures and Safet<\/h2>\n<p>A plain-English look at how a JSON Web Token is built, how its signature proves trust, and the attacks the spec warns about \u2014 with an offline tool to try it yourself.<\/p>\n<div id=\"pth-toc-placeholder\"><\/div>\n<\/p>\n<\/div>\n<div class=\"pth-hero-image\">\n\t<img data-no-lazy=\"1\"\n         src=\"https:\/\/schoolict.net\/tools\/wp-content\/uploads\/2026\/04\/free-offline-JWT-decoder-Article-1-800x447.jpeg\"\n         width=\"800\"\n         height=\"447\"\n         alt=\"free offline JWT decoder\"\n         fetchpriority=\"high\"\n         loading=\"eager\"\n         decoding=\"async\"\n         style=\"width:100%; height:auto; display:block;\">\n  <\/div>\n<\/div>\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2>Table of Contents<\/h2><nav><ul><li><a href=\"#\ud83d\udd34-the-three-parts-of-a-token-and-why-the-dots-matter\">\ud83d\udd34\u00a0The three parts of a token, and why the dots matter<\/a><\/li><li><a href=\"#\ud83d\udfe1-how-a-signature-proves-a-token-was-not-changed\">\ud83d\udfe1\u00a0How a signature proves a token was not changed<\/a><\/li><li><a href=\"#\ud83d\udfe2-hs-256-versus-rs-256-who-holds-the-key\">\ud83d\udfe2\u00a0HS256 versus RS256: who holds the key<\/a><ul><li><a href=\"#\ud83d\udfe2-a-rule-of-thumb\">\ud83d\udfe2\u00a0A rule of thumb<\/a><\/li><\/ul><\/li><li><a href=\"#\ud83d\udd34-the-attacks-the-standard-warns-about\">\ud83d\udd34\u00a0The attacks the standard warns about<\/a><\/li><li><a href=\"#\ud83d\udfe1-where-a-token-actually-sits-in-a-login-flow\">\ud83d\udfe1\u00a0Where a token actually sits in a login flow<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Last updated: July 2026<\/p>\n\n\n\n<h2 id=\"\ud83d\udd34-the-three-parts-of-a-token-and-why-the-dots-matter\" class=\"wp-block-heading\">\ud83d\udd34&nbsp;<strong>The three parts of a token, and why the dots matter<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every JSON Web Token is three chunks of text joined by two dots. Split on those dots and you get the header, the payload, and the signature. The header and payload start life as small JSON objects, and the signature is a cryptographic stamp computed over the first two. That layout is not a convention someone invented on a whim; it is written down in the official standard,&nbsp;<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7519\" rel=\"noreferrer noopener\" target=\"_blank\">IETF RFC 7519<\/a>.<\/p>\n\n\n\n<div style=\"float: left; width: 48%; min-width: 300px; margin-right: 20px; margin-bottom: 15px; position: relative; z-index: 10;\">\n    <style>\r\n.pth-yt-clean-JT6rpJec2Y8 {\r\n    position: relative;\r\n    width: 100%;\r\n    max-width: 100%;\r\n    aspect-ratio: 16 \/ 9;\r\n    background-color: #000;\r\n    border-radius: 8px;\r\n    overflow: hidden;\r\n    cursor: pointer;\r\n    box-shadow: 0 4px 12px rgba(0, 0, 0, 0.15);\r\n    transition: transform 0.3s ease;\r\n}\r\n.pth-yt-clean-JT6rpJec2Y8:hover {\r\n    transform: scale(1.0);\r\n}\r\n.pth-yt-clean-JT6rpJec2Y8 .pth-play-btn {\r\n    position: absolute;\r\n    top: 50%;\r\n    left: 50%;\r\n    width: 60px;\r\n    height: 40px;\r\n    background: rgba(255, 0, 0, 0.8);\r\n    border-radius: 10px;\r\n    transform: translate(-50%, -50%);\r\n    display: flex;\r\n    justify-content: center;\r\n    align-items: center;\r\n    transition: background 0.3s ease;\r\n    pointer-events: none;\r\n}\r\n.pth-yt-clean-JT6rpJec2Y8:hover .pth-play-btn {\r\n    background: #ff0000;\r\n}\r\n.pth-yt-clean-JT6rpJec2Y8 .pth-play-btn::before {\r\n    content: '';\r\n    width: 0;\r\n    height: 0;\r\n    border-top: 10px solid transparent;\r\n    border-bottom: 10px solid transparent;\r\n    border-left: 16px solid white;\r\n    margin-left: 4px;\r\n}\r\n<\/style>\r\n\r\n<div class=\"pth-yt-clean-JT6rpJec2Y8\"\r\n     data-vid=\"JT6rpJec2Y8\"\r\n     data-title=\"Prime Tool Hub Video Tutorial\"\r\n     role=\"button\"\r\n     tabindex=\"0\"\r\n     aria-label=\"Play video: Prime Tool Hub Video Tutorial\"\r\n     onclick=\"loadPTHVideo_JT6rpJec2Y8(this)\"\r\n     onkeydown=\"if(event.key==='Enter'||event.key===' ')loadPTHVideo_JT6rpJec2Y8(this)\">\r\n\r\n    <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/JT6rpJec2Y8\/hqdefault.jpg\"\r\n         alt=\"Prime Tool Hub Video Tutorial \u2014 Watch on YouTube\"\r\n         width=\"480\"\r\n         height=\"360\"\r\n         loading=\"lazy\"\r\n         style=\"width: 100%; height: 100%; object-fit: cover; border-radius: 8px;\">\r\n\r\n    <div class=\"pth-play-btn\"\r\n         role=\"img\"\r\n         aria-label=\"Play button\"><\/div>\r\n\r\n<\/div>\r\n\r\n<script data-no-optimize=\"1\" data-no-minify=\"1\" data-cfasync=\"false\">\r\nif (typeof window['loadPTHVideo_JT6rpJec2Y8'] !== 'function') {\r\n    window['loadPTHVideo_JT6rpJec2Y8'] = function(element) {\r\n        var vidId    = element.getAttribute('data-vid');\r\n        var vidTitle = element.getAttribute('data-title') || 'YouTube Video';\r\n        element.innerHTML = '\\x3Ciframe'\r\n            + ' src=\"https:\/\/www.youtube.com\/embed\/' + vidId + '?autoplay=1&rel=0\"'\r\n            + ' title=\"' + vidTitle + '\"'\r\n            + ' style=\"position:absolute;top:0;left:0;width:100%;height:100%;border:none;\"'\r\n            + ' allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\"'\r\n            + ' allowfullscreen'\r\n            + ' loading=\"lazy\"'\r\n            + '\\x3E\\x3C\/iframe\\x3E';\r\n    };\r\n}\r\n<\/script>\n    \n    <div style=\"margin-top: 15px; margin-bottom: 5px; text-align: center;\">\r\n   <a href=\"\/jwt-decoder-inspector\/\" \r\n      style=\"display: flex; width: 100%; justify-content: center; box-sizing: border-box; align-items: center; gap: 10px; background: linear-gradient(135deg, #3b82f6, #1d4ed8); color: #ffffff; font-family: 'Inter', sans-serif; font-weight: 700; font-size: 15px; padding: 14px 28px; border-radius: 10px; text-decoration: none; letter-spacing: 0.5px; box-shadow: 0 6px 15px rgba(37, 99, 235, 0.25); transition: all 0.3s ease;\" \r\n      onmouseover=\"this.style.transform='translateY(-3px)'; this.style.boxShadow='0 10px 25px rgba(37, 99, 235, 0.4)';\" \r\n      onmouseout=\"this.style.transform='translateY(0)'; this.style.boxShadow='0 6px 15px rgba(37, 99, 235, 0.25)';\">\r\n       <svg width=\"18\" height=\"18\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6\"><\/path><polyline points=\"15 3 21 3 21 9\"><\/polyline><line x1=\"10\" y1=\"14\" x2=\"21\" y2=\"3\"><\/line><\/svg>\r\n       OPEN TOOL NOW\r\n   <\/a>\r\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Before those JSON objects can travel inside a URL or an HTTP header, they are converted with base64url. This is a cousin of ordinary base64 that swaps two awkward characters and drops the trailing padding, so the result is safe to drop into a web address without anything getting mangled. A key point that trips people up: base64url is an encoding, not encryption. It scrambles nothing. Anyone who copies the middle chunk of a token can decode it back to readable JSON in a second, which is exactly what happens when you paste a token into a decoder. If base64 itself is new to you, the deeper mechanics are covered in our note on the&nbsp;<a href=\"https:\/\/schoolict.net\/tools\/base64-encoder-and-decoder\/\" rel=\"noreferrer noopener\" target=\"_blank\">base64 encoder and decoder<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the header might decode to something like a two-field object naming the algorithm and the type, and the payload to a set of claims about a user. The claims themselves follow a small shared vocabulary. Short three-letter names such as&nbsp;iss,&nbsp;sub,&nbsp;aud,&nbsp;exp,&nbsp;nbf&nbsp;and&nbsp;iat&nbsp;are the registered claims, and using them consistently is what lets one company&#8217;s token be understood by another company&#8217;s library.<\/p>\n\n\n\n<h2 id=\"\ud83d\udfe1-how-a-signature-proves-a-token-was-not-changed\" class=\"wp-block-heading\">\ud83d\udfe1&nbsp;<strong>How a signature proves a token was not changed<\/strong><\/h2>\n\n\n<figure class=\"pth-article-figure pth-img-left\" style=\"float:left; width:600px; max-width:100%; margin:4px 28px 16px 0; clear:left;\"><img decoding=\"async\" src=\"https:\/\/schoolict.net\/tools\/wp-content\/uploads\/2026\/04\/jwt-signature-check-800x447.jpeg\" alt=\"signature proves a token\" width=\"600\" height=\"338\" loading=\"lazy\" data-no-lazy=\"1\" class=\"pth-article-img\" style=\"width:100%;height:auto;display:block;border-radius:10px;border:1px solid #e2e8f0;\"><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If the payload is readable by anyone, what stops a user from editing their own token to promote themselves to admin? The signature. Here is the idea without the maths. The server takes the encoded header, a dot, and the encoded payload, and runs that whole string through a keyed hashing function together with a secret only the server knows. The output is the signature that becomes the third part of the token.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a token comes back later, the server repeats the exact same calculation with its secret and compares its result to the signature attached to the token. Match, and the token is genuine and untouched. If even a single character of the payload changed, the recomputed signature no longer lines up and the token is rejected. Because the attacker does not have the secret, they cannot forge a matching signature for their edited payload. This keyed-hash technique is called HMAC, and it is the same family of function you will find in our&nbsp;<a href=\"https:\/\/schoolict.net\/tools\/free-offline-secure-hash-generator-article\/\" rel=\"noreferrer noopener\" target=\"_blank\">guide to secure hashing<\/a>. Modern browsers expose it natively through the&nbsp;<a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/SubtleCrypto\" rel=\"noreferrer noopener\" target=\"_blank\">Web Crypto SubtleCrypto API<\/a>, which is how a fully offline tool can verify a signature without any server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Notice what a signature does and does not give you. It gives integrity and authenticity: proof the token came from the holder of the secret and was not altered. It does not give confidentiality. The payload is still plain to read. That is the crucial mental model. A signed token is like a sealed letter with a wax stamp; breaking the seal is obvious, but the writing was never hidden.<\/p>\n\n\n\n<h2 id=\"\ud83d\udfe2-hs-256-versus-rs-256-who-holds-the-key\" class=\"wp-block-heading\">\ud83d\udfe2&nbsp;<strong>HS256 versus RS256: who holds the key<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The header&#8217;s algorithm field decides how that signature is made, and the choice shapes your whole architecture. HS256, HS384 and HS512 are symmetric. One shared secret both signs and verifies. That is simple and fast, and it suits a single service that talks only to itself. The catch is that everyone who needs to verify a token must also hold the signing secret, and a secret spread across many services is a secret waiting to leak.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RS256 and ES256 are asymmetric. A private key signs, and a matching public key verifies. The private key stays locked on the issuing server, while the public key can be handed out freely to any service that only needs to check tokens. A payment service can verify a login token without ever being able to mint one. That separation is why large systems with many services usually reach for RS256. The trade-off is more moving parts: key pairs, rotation, and a way to publish the public key.<\/p>\n\n\n\n<h3 id=\"\ud83d\udfe2-a-rule-of-thumb\" class=\"wp-block-heading\">\ud83d\udfe2&nbsp;<strong>A rule of thumb<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83d\udd35 One service, talking to itself, wanting simplicity: symmetric HS256 is fine.<br>\ud83d\udfe0 Many services, where only one should be allowed to issue tokens: asymmetric RS256 keeps the signing power in one place.<br>\ud83d\udfe3 Whatever you choose, keep the secret or private key on the server. It should never ship inside a browser bundle or a mobile app.<\/p>\n\n\n\n<h2 id=\"\ud83d\udd34-the-attacks-the-standard-warns-about\" class=\"wp-block-heading\">\ud83d\udd34&nbsp;<strong>The attacks the standard warns about<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">JWTs have a small number of famous failure modes, and they are documented plainly in the JWT Best Current Practices,&nbsp;<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc8725\" rel=\"noreferrer noopener\" target=\"_blank\">IETF RFC 8725<\/a>. Knowing them turns a token from a black box into something you can reason about.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most infamous is the&nbsp;alg:none&nbsp;trick. Early libraries let a token declare that it used no algorithm at all, meaning no signature. An attacker would strip the signature, set the algorithm to none, and some servers happily trusted it. The fix is blunt: a verifier must decide in advance which algorithms it accepts and reject everything else, none included.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A subtler cousin is algorithm confusion. If a server is told to verify with a public RSA key but an attacker relabels the token as HS256, a naive library might use that public key as an HMAC secret. Since the public key is, by definition, public, the attacker can now sign valid tokens. The defence is to pin the expected algorithm rather than trusting whatever the header claims. A third class hides in the&nbsp;kid&nbsp;header, a key identifier that some systems feed straight into a file path or database lookup, opening the door to injection if it is not sanitised. None of these are exotic; they are the everyday checklist of anyone reviewing a token system, which is why a good auditing tool surfaces them for you.<\/p>\n\n\n\n<h2 id=\"\ud83d\udfe1-where-a-token-actually-sits-in-a-login-flow\" class=\"wp-block-heading\">\ud83d\udfe1&nbsp;<strong>Where a token actually sits in a login flow<\/strong><\/h2>\n\n\n\n<div style=\"float: left; width: 48%; min-width: 300px; margin-right: 20px; margin-bottom: 15px;\">\n\t<div class=\"pth-inline-card\" data-url=\"\/jwt-decoder-inspector\/\"><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Theory sticks better when you can place it in a real journey. A user signs in with a password. The server checks it once, then issues a short-lived access token, often valid for fifteen minutes, carrying the user&#8217;s id and roles. The browser attaches that token to each request, and every service can verify it without hitting the login database again. That statelessness is the whole appeal of JWTs at scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Short lifetimes raise an obvious question: what happens when the token expires mid-session? That is the job of a separate, longer-lived refresh token, kept somewhere safer, whose only purpose is to quietly request a new access token. The access token stays brief so a leaked one is useless within minutes, while the refresh token is guarded more tightly. Understanding this two-token dance explains why the&nbsp;exp&nbsp;claim is so central, and why a token without one is a quiet liability rather than a convenience. When you want to see any of this for yourself, the&nbsp;<a href=\"https:\/\/schoolict.net\/tools\/jwt-decoder-inspector\/\" rel=\"noreferrer noopener\" target=\"_blank\">JWT Studio<\/a>&nbsp;lets you decode, sign and audit tokens entirely in your browser, so the concepts on this page become something you can poke at rather than just read about.<\/p>\n\n\n\n<style>\n.pth-faq-section{margin:50px auto 40px;font-family:inherit;max-width:1480px;padding:0 20px;box-sizing:border-box}\n.pth-faq-header{font-size:1.8rem;font-weight:800;color:#0f172a;margin-bottom:25px;border-bottom:2px solid #e2e8f0;padding-bottom:10px;display:flex;align-items:center;gap:10px}\n.pth-faq-grid{display:grid;grid-template-columns:1fr;gap:20px}\n@media(min-width:768px){.pth-faq-grid{grid-template-columns:repeat(2,1fr)}}\n@media(min-width:1024px){.pth-faq-grid{grid-template-columns:repeat(3,1fr)}}\n.pth-faq-card{background:#f8fafc;padding:24px;border-radius:12px;border:1px solid #e2e8f0;transition:transform .2s ease;break-inside:avoid}\n.pth-faq-card:hover{transform:translateY(-3px);box-shadow:0 4px 12px rgba(0,0,0,.05)}\n.pth-faq-q{color:#0f172a;font-size:1rem;font-weight:700;margin:0 0 12px;line-height:1.4}\n.pth-faq-a{margin:0;font-size:.95rem;color:#1e293b;line-height:1.6;font-weight:500}\n<\/style>\n<div class=\"pth-faq-section\">\n  <div class=\"pth-faq-header\">\u2753 Frequently Asked Questions<\/div>\n  <div class=\"pth-faq-grid\">\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Is a JWT encrypted?<\/p>\n      <p class=\"pth-faq-a\">A standard JWT is signed, not encrypted. The payload is base64url text that anyone can decode and read. Signing proves the token was not altered; it does not hide the contents.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Can someone change the payload of my token?<\/p>\n      <p class=\"pth-faq-a\">They can edit the text, but they cannot produce a matching signature without the secret or private key. A properly configured server recomputes the signature and rejects any token that was changed.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Why are the claims only three letters long?<\/p>\n      <p class=\"pth-faq-a\">Names like iss, sub, exp and iat are the registered claims defined in RFC 7519. Sharing this vocabulary lets tokens issued by one system be understood by libraries written by another.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Should I use HS256 or RS256?<\/p>\n      <p class=\"pth-faq-a\">HS256 suits a single service that both issues and verifies tokens. RS256 fits many services, because a private key signs while a widely shared public key verifies, keeping issuing power in one place.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">What is the alg:none attack?<\/p>\n      <p class=\"pth-faq-a\">It is a token that declares no signature at all. Servers that trust it can be handed forged tokens. The fix is to accept only a fixed list of algorithms and reject none, as RFC 8725 advises.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Where should the secret key live?<\/p>\n      <p class=\"pth-faq-a\">Only on the server. If a signing secret or private key is bundled into a browser app or mobile binary, anyone can extract it and mint their own valid tokens, which defeats the entire scheme.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Why do access tokens expire so quickly?<\/p>\n      <p class=\"pth-faq-a\">A short life limits the damage of a leaked token. A separate refresh token, stored more securely, is used to obtain fresh access tokens without asking the user to log in again.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">Can I inspect tokens without sending them online?<\/p>\n      <p class=\"pth-faq-a\">Yes. Because decoding and HMAC verification are available in the browser through the Web Crypto API, a client-side tool can read and check tokens without any server contact.<\/p>\n    <\/div>\n    <div class=\"pth-faq-card\">\n      <p class=\"pth-faq-q\">What is the signature actually computed over?<\/p>\n      <p class=\"pth-faq-a\">Over the encoded header, a dot, and the encoded payload together. Change either part and the signature no longer matches, which is what makes tampering detectable.<\/p>\n    <\/div>\n  <\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>How JSON Web Tokens Really Work: Structure, Signatures and Safet A plain-English look at how a JSON Web Token is built, how its signature proves trust, and the attacks the spec warns about \u2014 with an offline tool to try it yourself. Last updated: July 2026 \ud83d\udd34&nbsp;The three parts of a token, and why the &#8230; <a title=\"Free Offline JWT Decoder: How JSON Web Tokens Really Work\" class=\"read-more\" href=\"https:\/\/schoolict.net\/tools\/free-offline-jwt-decoder-article\/\" aria-label=\"Read more about Free Offline JWT Decoder: How JSON Web Tokens Really Work\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":2124,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-2114","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-developer-tools"],"_links":{"self":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/posts\/2114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/comments?post=2114"}],"version-history":[{"count":0,"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/posts\/2114\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/media\/2124"}],"wp:attachment":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/media?parent=2114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/categories?post=2114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/tags?post=2114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}