Paste a token to inspect what it claims.
A JWT has three Base64URL parts separated by dots: a header, a payload of claims and a signature. The tool decodes the first two and prints them as formatted JSON. Standard time claims for issued at, not before and expiry are converted into readable dates with a relative note, and you see at once whether the token has expired.
The signature is not verified, because that needs the secret or the public key. Treat decoded claims as unverified information. Never paste live production tokens into tools you do not trust, and this one works entirely in your browser.
No. Anyone can create a token with any content. Validity depends on the signature, which your server must verify with the right key.
A standard signed JWT is only encoded, not encrypted. Anyone with the token can read the claims, so never put secrets in them.
It is the authorization scheme in the HTTP header. The tool strips that word automatically.