Decode a JWT's header and payload — no signature verification.
Runs entirely in your browser — nothing is uploaded.
This decodes the token’s contents only — it does not verify the signature. A decoded token here proves nothing about whether it’s genuine.