Is decoding a JWT the same as verifying it?
No. Decoding just reads the Base64URL-encoded header and payload — anyone can do that without a key. Verifying checks the signature against a secret or public key to confirm the token wasn't tampered with. This tool does both: paste a token to decode it instantly, then optionally add the secret (HS256/384/512) or public key in PEM form (RS256/384/512, ES256/384/512) to verify the signature too.