# JWT decoder

> Inspect a JWT header and payload without trusting it.

[Open tool](https://www.toolcabana.com/mg/jwt-decoder) · [Developer and data](https://www.toolcabana.com/mg/category/developer-and-data)

Tool ID: jwt-decoder. Requested language: mg. Description language: en. Complete guide translation: no; untranslated sections use English.

## Overview (en)

JWT decoder splits a JSON Web Token into its header and payload and shows them as formatted JSON. The exp, iat and nbf claims are also listed as UTC times, and exp is compared with this computer's clock. The signature is never verified, so treat the decoded contents as untrusted.

## Supported tasks (en)

Shows the header and payload without verifying the signature. exp, iat and nbf are also shown as UTC times. Comparing exp with this computer's clock is not a signature check.

## Steps (en)

1. Type or paste your source, or load an example.
2. Change the basic settings or open Advanced mode to fine-tune the result.
3. Review and copy or download your result. Pause Live results to run manually. Sources or individual settings above 20,000 characters require an explicit run.

## Settings

- JWT Base64URL encoding (en; key: urlSafe; type: checkbox)

## Limitations (en)

Text operations generally accept up to 2,000,000 characters. Individual parsers, generators and formulas apply additional limits shown by their controls.

## Example input

```text
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJleGFtcGxlIiwiZXhwIjoxODAwMDAwMDAwfQ.demo
```

## Privacy and connections (en)

This operation processes its source in your browser. Copy and download are explicit actions; source input is not saved in an account or history.

## Questions (en)

### Does the JWT decoder verify the signature?

No. It only decodes the header and payload. The signature, issuer and authorization are not checked, so a decoded token is not proof that it is genuine.

### How can I see when a JWT expires?

If the payload has numeric exp, iat or nbf claims, each is shown as a UTC date and time. The tool also states whether exp is earlier or later than this computer's current clock.

### Why does the JWT decoder say the token needs three sections?

A signed JWT has three dot-separated parts: header, payload and signature. Tokens with a different number of parts, or segments that are not valid Base64URL JSON, are rejected.

### Where is my input processed?

This operation processes its source in your browser. Copy and download are explicit actions; source input is not saved in an account or history.

### What are the input limits?

Text operations generally accept up to 2,000,000 characters. Individual parsers, generators and formulas apply additional limits shown by their controls.

## Related tools

- [Certificate decoder](https://www.toolcabana.com/mg/certificate-decoder)
- [HTML entity encoder](https://www.toolcabana.com/mg/html-entities)
- [UUID generator](https://www.toolcabana.com/mg/uuid-generator)
- [URL encoder decoder](https://www.toolcabana.com/mg/url-encode)
