Important Security Notice
⚠️ Decoding a JWT does not verify its signature. Never assume a token is valid merely because it can be parsed client-side. Always verify token signatures on your server.
What is a JSON Web Token (JWT)?
A JWT is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object. JWTs consist of three parts separated by dots: Header, Payload, and Signature.