{"uid":"cap_RfgywatmX-WlYC8vF2byB","slug":"47620-jwt-decode-api-0e2bb1f3","name":"47620 JWT Decode API","description":"Decode a JWT (JSON Web Token): returns the header, payload and the extracted claims (subject sub, issuer iss, audience aud, expiration exp with `expired` flag and seconds remaining, issued-at iat, not-before nbf, algorithm alg, key id kid). Decode-only — the signature is NOT verified, so claims are informational. Pass the token via ?token=<jwt> (query param, no length limit).","url":"https://47620.xyz/x/util/jwt-decode?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"fields":{"type":"string","description":"Optional comma-separated top-level response keys to keep (e.g. \"health,slot,solUsd\"). Omit for the full payload."}},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type","example"],"properties":{"type":{"type":"string","const":"json"},"example":{"type":"object","required":["ok","endpoint"],"properties":{"ok":{"type":"boolean"},"endpoint":{"type":"string"}},"additionalProperties":true}},"additionalProperties":false}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_AJioEktC7KhEq8ITei7KA","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Decodes a JWT token and extracts header, payload, and standard claims (sub, iss, aud, exp, iat, nbf, alg, kid) with expiration status — without verifying the signature.","exampleAgentPrompt":"Can you decode this JWT for me and tell me whether it's expired, who the issuer is, and what the subject claim says: eyJhbGciOiJSUzI1NiIsImtpZCI6ImFiYzEyMyJ9.eyJzdWIiOiJ1c2VyXzQ1NiIsImlzcyI6Imh0dHBzOi8vYXV0aC5leGFtcGxlLmNvbSIsImV4cCI6MTcwMDAwMDAwMH0.signature","exampleUseCases":[{"title":"Debugging expired auth token","prompt":"I've got a JWT that keeps getting rejected — can you decode it and tell me whether it's expired and how long ago it expired? Here's the token: eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ1c2VyXzEyMyIsImV4cCI6MTY4MDAwMDAwMH0.sig"},{"title":"Inspecting token issuer and audience","prompt":"Can you decode this JWT and tell me who issued it, what audience it's meant for, and what algorithm was used to sign it? Token: eyJhbGciOiJSUzI1NiIsImtpZCI6ImtleS0xIn0.eyJpc3MiOiJodHRwczovL2lkcC5leGFtcGxlLmNvbSIsImF1ZCI6ImFwaS5leGFtcGxlLmNvbSJ9.sig"},{"title":"Extracting user identity from token","prompt":"I need to know the subject (user ID) and when this token was issued — please decode this JWT and pull out the sub and iat claims: eyJhbGciOiJFUzI1NiJ9.eyJzdWIiOiJ1c2VyXzc4OSIsImlhdCI6MTY5MDAwMDAwMH0.sig"}],"resultDescription":"A JSON object containing the decoded JWT header (including algorithm and key ID), the full payload with all claims, and individually extracted standard claims: subject (sub), issuer (iss), audience (aud), expiration (exp) with an 'expired' boolean flag and seconds remaining until/since expiry, issued-at (iat), not-before (nbf), algorithm (alg), and key ID (kid).","failureModes":["Malformed or non-JWT string returns an error response","Missing ?token= query parameter returns a bad request error","Very long tokens may hit URL length limits depending on client configuration","No signature verification — tampered tokens will still decode without error","Non-standard or nested JWTs may not parse all claims correctly"],"whenToPreferThis":"Use this endpoint when you need to quickly inspect the contents and expiration status of a JWT without needing signature verification — ideal for debugging, logging, or extracting claims for informational purposes. Prefer this over a full JWT validation endpoint when you already trust the token source or just need to read its payload. It is also useful for agents that need to extract a user ID, issuer, or expiration time from a token at runtime without maintaining signing keys.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:46:34.190Z","isFirstParty":false,"canonicalSlug":"47620-jwt-decode-api-0e2bb1f3"}