A JWT isn't just JSON you can inspect. It's a live bearer token. Here's a safer way to decode one.
A few days ago I was reviewing a bug with a teammate. They wanted to see what was inside an access token, so they copied it into the first JWT decoder Google returned.
It wasn't a dummy token.
It was a production access token with almost an hour...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3614374