JWT decoder
Inspect a JWT header and payload without trusting it.
JWT decoder
Type or paste to update the result automatically.
Your result appears here
Type, paste, or use an example. Copy your result when it is ready.
Ako používať JWT decoder
JWT decoder splits a JSON Web Token into its header and payload and shows them as formatted JSON. The exp, iat and nbf claims are also listed as UTC times, and exp is compared with this computer's clock. The signature is never verified, so treat the decoded contents as untrusted.
- Type or paste your source, or load an example.
- Change the basic settings or open Advanced mode to fine-tune the result.
- Review and copy or download your result. Pause Live results to run manually. Sources or individual settings above 20,000 characters require an explicit run.
Funkcie nástroja
Shows the header and payload without verifying the signature. exp, iat and nbf are also shown as UTC times. Comparing exp with this computer's clock is not a signature check.
- JWT Base64URL encoding
- Set this value for your task.
Obmedzenia a spracovanie
Text operations generally accept up to 2,000,000 characters. Individual parsers, generators and formulas apply additional limits shown by their controls.
Ukážkový vstup
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJleGFtcGxlIiwiZXhwIjoxODAwMDAwMDAwfQ.demo
Časté otázky
Does the JWT decoder verify the signature?
No. It only decodes the header and payload. The signature, issuer and authorization are not checked, so a decoded token is not proof that it is genuine.
How can I see when a JWT expires?
If the payload has numeric exp, iat or nbf claims, each is shown as a UTC date and time. The tool also states whether exp is earlier or later than this computer's current clock.
Why does the JWT decoder say the token needs three sections?
A signed JWT has three dot-separated parts: header, payload and signature. Tokens with a different number of parts, or segments that are not valid Base64URL JSON, are rejected.
Where is my input processed?
This operation processes its source in your browser. Copy and download are explicit actions; source input is not saved in an account or history.
What are the input limits?
Text operations generally accept up to 2,000,000 characters. Individual parsers, generators and formulas apply additional limits shown by their controls.