What a JWT contains
A JSON Web Token has three Base64URL parts separated by dots: a header (algorithm and type), a payload (claims such as sub, iat, exp) and a signature. Anyone holding the token can read the first two parts, so never put secrets in them.
What this tool does not do
It decodes but does not verify the signature. A decoded token is not proof that the token is authentic. Verify signatures on your server with the correct key.
Time claims
iat (issued at) and exp (expiration) are seconds since 1970 in UTC. The tool converts them to readable times and flags expired tokens using your device clock.