JWT decoder

Read the header and payload, without pretending that proves anything

Decode the three segments of a JSON Web Token and read the registered claims, with expiry and not-before times resolved against your clock. The signature is never verified, and the page says so plainly, because decoding proves nothing about authenticity.