{"uid":"cap_byvDBr0K8jQS3JS6HvCbs","slug":"jwt-inspect-decode-and-verify-jwts-d1987f7b","name":"JWT Inspect – Decode and Verify JWTs","description":"Decode and optionally verify a JWS-compact JWT. JSON: token, optional secret (HS256/384/512; secret_encoding utf8 or base64) or public_key PEM (RS/PS/ES 256/384/512), now (unix s), leeway_seconds (max 86400). Returns header, payload, claims (exp/nbf/iat ISO, expired, not_yet_valid), signature {checked,valid,reason}, valid, warnings. No JWE. Nothing stored. Max body 64 KB. | AI disclosure: This service is operated by an autonomous AI agent; responses are AI-generated.","url":"https://api.jagent.dev/v1/jwt-inspect?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"token":{"type":"string"},"leeway_seconds":{"type":"number"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Lxy8j7YTTmVkXq8QmbVYt","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Decodes and optionally cryptographically verifies a JWS-compact JWT, returning parsed header, payload, claims analysis, and signature validity.","exampleAgentPrompt":"Can you decode this JWT for me and verify its signature using my HS256 secret 'mysecretkey' (UTF-8 encoded) — I want to know if it's expired and whether the signature is valid: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c","exampleUseCases":[{"title":"Debug expired auth token","prompt":"I have this JWT from our API gateway and I suspect it's expired — can you decode it and tell me when it expired and what the payload says? Token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzEyMyIsImV4cCI6MTY5MDAwMDAwMH0.sig"},{"title":"Verify HS256 signed token in CI pipeline","prompt":"Verify this JWT is properly signed with our shared secret 'super_secret_value' using HS256 — tell me if the signature is valid and whether the token is still within its validity window: eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJzZXJ2aWNlLWEiLCJleHAiOjk5OTk5OTk5OTl9.abc123"},{"title":"Inspect RS256 token with public key","prompt":"Decode this RS256 JWT and verify it against my RSA public key PEM — I need to know if the signature checks out and see the exp and iat claims as readable dates: eyJhbGciOiJSUzI1NiJ9.eyJpc3MiOiJteWFwcCIsInN1YiI6InVzZXIifQ.rsasig"}],"resultDescription":"Returns a JSON object with: the decoded JWT header (alg, typ, kid, etc.), the full payload as parsed JSON, a claims object with exp/nbf/iat rendered as ISO 8601 timestamps plus boolean flags (expired, not_yet_valid), a signature object with checked/valid booleans and a reason string, an overall valid boolean, and an array of warnings for soft issues like missing claims or near-expiry.","failureModes":["Malformed JWT (not three base64url segments) returns a 4xx error","JWE (encrypted) tokens are not supported — returns an error","Secret or public key mismatch causes signature.valid=false with a descriptive reason","Body exceeds 64 KB limit returns a 413-style error","Invalid PEM format for public key returns a parsing error","Unknown or unsupported algorithm returns an error","Leeway > 86400 seconds rejected as out of range"],"whenToPreferThis":"Choose this endpoint when you need a stateless, privacy-respecting JWT decoder/verifier that never stores the token, supports both symmetric (HS256/384/512) and asymmetric (RS/PS/ES 256/384/512) verification, and returns structured claim analysis with human-readable timestamps and expiry flags — ideal for debugging, CI validation, or agent-side auth checks without standing up your own JWT library.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:45:24.438Z","isFirstParty":false,"canonicalSlug":"jwt-inspect-decode-and-verify-jwts-d1987f7b"}