Private/ConvertFrom-AACJwt.ps1

function ConvertFrom-AACJwt {
    <#
    .SYNOPSIS
        Decodes the claims (payload) of a JWT, without validating its signature.
    .DESCRIPTION
        This is for reading display-only information out of an id_token (like the
        signed-in account name and tenant ID) after it has already been received
        directly from Microsoft's token endpoint over TLS. It is not a general
        purpose token validator and must never be used to authorize anything on
        its own - the access_token itself is what the resource server (Azure
        Resource Manager) validates.
    #>

    [CmdletBinding()]
    [OutputType([pscustomobject])]
    param(
        [Parameter(Mandatory)]
        [string] $Token
    )

    $segments = $Token.Split('.')
    if ($segments.Count -lt 2) {
        throw 'The supplied token is not a well-formed JWT (expected at least a header and a payload segment).'
    }

    $payload = $segments[1].Replace('-', '+').Replace('_', '/')
    switch ($payload.Length % 4) {
        2 { $payload += '==' }
        3 { $payload += '=' }
    }

    $json = [System.Text.Encoding]::UTF8.GetString([Convert]::FromBase64String($payload))
    return $json | ConvertFrom-Json
}