Answer
Anyone holding a signed JWT can read its claims: the payload is only base64url-encoded, not encrypted. The signature proves the claims were not changed.
Also accepted: base64 for base64url; modified, tampered with, altered for changed.
Why
Do not put secrets or sensitive personal data in a JWT; it ends up in browser storage, logs and proxies. If the claims must be hidden, encrypt them (JWE) or use an opaque token that points to server-side data.