This only decodes the token locally — it does not verify the signature. Never treat an unverified token as trustworthy.