Decode a token, read its claims in local time, and actually verify the signature — HMAC, RSA or ECDSA.