JWT trust boundaries
Decoding is not verification
JWT header and payload segments are Base64URL-encoded and readable without a secret. Treat decoded claims as untrusted until the HS256 signature matches a trusted secret and the application checks issuer, audience, expiry, and other policy requirements.
Use an adequately long random secret
HS256 security depends on the shared secret. A memorable password is not equivalent to a uniformly random 256-bit key. The verifier below reports entered secret length, but key generation and secret storage still belong in a secure application environment.
Time claims need the right clock and policy
exp, nbf, and iat use NumericDate seconds. Production systems often allow a small clock-skew window and may require issuer/audience checks in addition to time validity. The browser panel shows the raw claim status but does not implement your application’s authorization policy.