Decode before you trust
The decoder separates algorithm/type, expiry/activity state, registered claims, raw header/payload JSON, and signature metadata so token structure is readable at a glance.
Verification boundary
Decoding is not signature verification. Validate the cryptographic signature with the intended key and algorithm, then enforce issuer, audience, time, nonce/replay, and application authorization policy separately.
Trust and standards boundaries
Formatting is not schema validation, Base64 is not encryption, URL normalization is not a privacy guarantee, UUID metadata is not provenance, and decoded JWT claims are not trusted until cryptographic and application-specific validation succeeds. RS256 tools accept explicit PEM key formats and do not fetch issuer keys or make authorization decisions.
How to use this JWT Decoder
Paste a compact JWT and compare the encoded token with separate header, payload, signature-size, and registered time-claim panels.