Splits and decodes the header, payload, and signature of a JWT, interprets the standard claims (iss, sub, aud, exp, nbf, iat, jti) with configurable clock tolerance, and verifies the signature locally with HMAC (HS256/384/512), RSA (RS256/384/512), or EC (ES256/384) when you supply a compatible key. It explicitly distinguishes between decoded, not verified, verified, invalid signature, expired token, not-yet-valid token, malformed token, and disallowed algorithm — it never confuses decoding with verifying. It rejects alg:none by default and never mixes algorithm families (HMAC/RSA/EC) with a key of another type.
The token, keys, and secrets stay on your device.
A decoded JWT isn't necessarily authentic. Authenticity requires verifying its signature with a trusted key.
or upload a file with the token
The data is processed on your device and is never sent to the server.