What does a JWT decoder reveal?
A JWT decoder separates a JSON Web Token into its header, payload, and signature segments, then turns the Base64URL-encoded header and payload into readable JSON. That exposes claims such as issuer, audience, subject, roles, and expiry so a token can be inspected while debugging authentication.
Decoding follows RFC 7519 and RFC 7515 and runs locally in the browser. It does not verify the signature, trusted issuer, audience, revocation state, or expiry, so readable claims are not evidence that a token is genuine. Signature validation still requires the correct secret or public key and policy checks.