Inspect a JSON Web Token's header and payload.
This only decodes the token — it doesn't verify the signature.