Decoding is only half the job. When you are debugging an authentication failure, work through the same checks the server should be performing, in this order.
1. Expiry. Confirm exp exists and is in the future, and that iat is not in the future either. A missing exp means the token never expires โ a stolen copy stays valid forever.
2. Algorithm. The alg header must match exactly what your service expects. Be suspicious of none, of unexpected algorithm families, and of a token whose header was swapped while the payload stayed the same.
3. Issuer and audience. iss should identify the system that issued the token and aud should contain your service. Tokens minted for one service must not be accepted by another: that is the confused-deputy problem in practice.
4. Scopes and roles. Check that the permissions in the token are the minimum the operation needs. A token carrying administrative scopes where read-only access would do turns any leak into a much larger incident.
5. Lifetime and revocation. Short lifetimes limit the damage of a leak. Where tokens are long-lived, look for a jti claim โ without a unique token id there is no practical way to blacklist a single token after a logout or a breach.
The security findings above the decoded output automate these checks, so you can see at a glance whether the token you are holding would pass a careful review.