Do not paste production secrets
Local processing reduces exposure, but a browser tool is not a secrets manager. Use test data for private keys, session tokens, credentials, customer data, and production payloads.
- Base64 is encoding, not encryption.
- Decoded JWT claims are not proof that a signature is valid.
- Rotate any secret accidentally shared with an untrusted service.