// paste a JWT and the decoded header + payload appear here
Paste the shared secret used to sign the token, then check.