Security basics
What a JWT decoder can and cannot tell you
Understand the difference between reading a token payload and verifying its authenticity.
Decoding is not verification
A JSON Web Token commonly contains a readable header and payload encoded with base64url. Anyone who has the token can often decode those parts.
The signature must be verified with the correct algorithm and key before trusting claims. A decoded payload alone does not prove who issued it or whether it has been changed.
Handle tokens carefully
Tokens can contain sensitive claims. Avoid pasting production credentials into tools you do not trust, and never share a token in logs or screenshots.