Decoding is not verifying
The JWT Decoder shows a token's header and claims, which is useful for checking expiry or scopes. It does not verify the signature; only the service holding the signing key can confirm a token is genuine.
Hashes and passwords
SHA-256 is suited to checksums and integrity checks. For storing user passwords, use a deliberately slow algorithm such as Argon2 or bcrypt on your server. Generated passwords use cryptographic randomness, not Math.random().
