Decode a JWT header + payload and check expiry — locally, safely.
Signature is not verified — this inspects claims only. The token never leaves your browser.
Runs entirely in your browser — nothing you type here is uploaded.