Tools

Read and verify a JWT

Opens the three parts, checks expiry and claims, and verifies the signature if you give it a key.

Opening a token proves nothing: anyone can craft one that says whatever they want. Until you verify the signature with a key, what you see is what the token claims about itself.