{"uid":"cap_hEdbqk_9aVPz8VRW8DLd9","slug":"jwt-decoder-header-claims-no-verification-6a646522","name":"JWT Decoder (Header + Claims, No Verification)","description":"Decode a JWT's header and claims — WITHOUT verifying it — Genesis402 / UnyKorn Operator Network","url":"https://twin.unykorn.org/decode-jwt?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"params":{"type":"object","properties":{"token":{"type":"string"}}}}},"responseSchema":{"type":"json","example":{"ok":true,"type":"decode-jwt","receipt":{"tx_hash":"0x<64hex>","amount_usd":0.002,"receipt_id":"g402-<16hex>"},"generated_at":"<iso8601>"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_g3ewOnsvNWlb1GPAYysoz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Decodes a JWT token's header and claims payload without performing signature verification","exampleAgentPrompt":"Can you decode this JWT for me and show me what's in the header and claims? Here's the token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c — I just want to read the payload, not verify the signature.","exampleUseCases":[{"title":"Inspect expired auth token claims","prompt":"I have this JWT from a failed API request and I want to know what subject, expiry, and roles it contains — can you decode it without verifying it? Token: eyJhbGciOiJSUzI1NiIsImtpZCI6ImFiYzEyMyJ9.eyJzdWIiOiJ1c2VyXzQ1NiIsInJvbGVzIjpbImFkbWluIl0sImV4cCI6MTcwMDAwMDAwMH0.signature"},{"title":"Debug JWT algorithm and key ID","prompt":"What algorithm and key ID are in the header of this JWT? eyJhbGciOiJFUzI1NiIsImtpZCI6ImtleS0yMDI0LTAxIn0.eyJpc3MiOiJteWFwcC5pbyIsImF1ZCI6ImFwaS5teWFwcC5pbyJ9.sig — I'm troubleshooting a signature mismatch and need to see the header fields."},{"title":"Extract user identity from bearer token","prompt":"Pull out the user ID, email, and any scope claims from this bearer token so I can see who it belongs to: eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyX2lkIjoiOTk5IiwiZW1haWwiOiJhbGljZUBleGFtcGxlLmNvbSIsInNjb3BlIjoicmVhZDp3cml0ZSJ9.xyz"}],"resultDescription":"Returns a JSON object containing the decoded JWT header fields (e.g. alg, typ, kid) and the decoded claims payload (e.g. sub, iat, exp, iss, aud, custom claims), along with a transaction receipt confirming the x402 micropayment. No signature verification is performed — the output reflects raw encoded content only.","failureModes":["Malformed or non-JWT string input may return an error or unparseable result","Token with missing dot-separated segments will fail to decode","Base64url decoding errors if the token is truncated or corrupted","Network or payment processing failure resulting in HTTP 402 or 5xx response"],"whenToPreferThis":"Use this endpoint when you need to quickly inspect the contents of a JWT — such as reading claims, checking expiry, or identifying the algorithm — without needing to validate the signature. Prefer it over full JWT verification libraries when you only need to read the payload, when the signing key is unavailable, or when operating in a lightweight agent pipeline that just needs to extract fields like sub, iat, exp, or custom claims. Not appropriate when security-sensitive decisions depend on token authenticity.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T18:55:42.650Z","isFirstParty":false,"canonicalSlug":"jwt-decoder-header-claims-no-verification-6a646522"}