Before you start
What you need
One compact JWT containing readable JSON header and payload sections.
Developer & Data
Read a JWT header and payload locally with an explicit signature-not-verified warning.
No black box
The first two Base64URL sections are decoded as strict UTF-8 JSON. The signature section is not checked and no issuer keys are requested.
Before you start
One compact JWT containing readable JSON header and payload sections.
What you get
Formatted header and payload claims marked signature_verified: false.
Keep in mind
Decoded claims are untrusted until a server verifies algorithm, signature, issuer, audience, time claims, and authorization policy.
Practical uses
Verified data boundary
The published contract marks these tools as client-only processing. Nirmion uses the API only to confirm that this workspace is enabled in MySQL; source values and results are not sent to Flask.