Decodes a JWT and returns the payload (middle segment) as a parsed object. Uses base64url decoding per RFC 7519 and UTF-8 decoding so non-ASCII fields (e.g. unicode usernames) round-trip correctly.

Error with a clear message if the token is malformed, non-base64url, or the payload is not valid JSON.