Anatomy of a JWT
The header and the payload are JSON, Base64URL-encoded. They are not encrypted: anyone holding the token can read them, which is all a decoder does. The signature is computed over header.payload with a key, and it is the only part that says the token was issued by who it claims.
Decoded is not verified
A server must verify the signature with the expected algorithm and key, and then check exp, nbf, aud and iss. Reading the claims from an unverified token and trusting them is the classic JWT vulnerability. This page checks HMAC signatures (HS256, HS384, HS512) when you enter the secret. For RS256, ES256, PS256 or EdDSA it says the signature was not checked, and never reports such a token as valid.
Handling tokens
A token that has not expired is a credential. The token and the secret you type here stay in memory: they are not written to storage, and "Copy link" is not offered on this page. Prefer expired or test tokens when debugging, and see Verify privacy for how to confirm what this page does with them.