About the signature: The signature cannot be verified in your browser without the server's secret key. This tool decodes the header and payload only, which are not encrypted — anyone with the token can already read this information. Never assume a JWT's contents are private.