Read the header, payload, and expiry of a token.
JWT
This token is unsigned (alg “none”). Anything could have written it, and a server must never accept it.
Verify
HS256, HS384, and HS512 take the shared secret. RS, PS, ES, and EdDSA take the public key, as PEM, a certificate, or a JWK or JWKS set.
Header
Payload