Decode a JWT header and payload in your browser. Signature is shown but not verified — use this for debugging Entra ID / API tokens, not as a security check.