{"uid":"cap_v_-iDFtlQ_4PgXX7cdX89","slug":"duo-data-utilities-jwt-decoder-0a5806b9","name":"Duo Data Utilities – JWT Decoder","description":"Decode a JSON Web Token without verifying it: returns the header, the claims, the signature length and algorithm, and a computed view of the time claims — whether exp has passed, whether nbf is in the future, and the remaining lifetime in seconds against a supplied or current instant. Reports structural problems such as a missing part, invalid base64url or an alg of none. It does not and cannot verify the signature; do not use it to decide trust.","url":"https://api.duoleads.com/v1/code/jwt?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["token"],"properties":{"at":{"type":"string","maxLength":64,"description":"Instant to evaluate exp/nbf against: RFC 3339 or epoch seconds. Default now."},"token":{"type":"string","maxLength":8192,"description":"The JWT to decode (not verified). At most 8192 characters."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["ok","route","version","data","meta"],"properties":{"ok":{"const":true},"data":{"type":"object","required":["valid_structure","header","payload","alg","typ","kid","signature_bytes","parts","claims","time","signature_verified","warnings","reason"],"properties":{"alg":{"type":["string","null"]},"kid":{"type":["string","null"]},"typ":{"type":["string","null"]},"time":{"type":"object","required":["evaluated_at","expired","not_yet_valid","expires_in_seconds","age_seconds"],"properties":{"expired":{"type":["boolean","null"]},"age_seconds":{"type":["integer","null"]},"evaluated_at":{"type":"string"},"not_yet_valid":{"type":["boolean","null"]},"expires_in_seconds":{"type":["integer","null"]}}},"parts":{"type":"integer"},"claims":{"type":"object","required":["iss","sub","aud","exp","nbf","iat","jti"],"properties":{"aud":{"type":["string","array","null"],"items":{"type":"string"},"description":"RFC 7519 4.1.3: string or array of strings; null when absent"},"exp":{"type":["number","null"]},"iat":{"type":["number","null"]},"iss":{"type":["string","null"]},"jti":{"type":["string","null"]},"nbf":{"type":["number","null"]},"sub":{"type":["string","null"]}}},"header":{"type":["object","null"],"description":"caller-supplied content echoed exactly as decoded: members are not typed"},"reason":{"type":["string","null"]},"payload":{"type":["object","null"],"description":"caller-supplied content echoed exactly as decoded: members are not typed"},"warnings":{"type":"array","items":{"type":"string"}},"claim_errors":{"type":"array","items":{"type":"object","required":["claim","reason"],"properties":{"claim":{"type":"string"},"reason":{"type":"string"}}}},"signature_bytes":{"type":"integer"},"valid_structure":{"type":"boolean"},"signature_verified":{"type":"boolean"}}},"meta":{"type":"object","required":["request_id","computed_at","price_usd","deterministic","disclaimer"],"properties":{"sources":{"type":"array","items":{"type":"object","required":["id","version","published"]}},"price_usd":{"type":"string"},"disclaimer":{"type":"string"},"request_id":{"type":"string"},"computed_at":{"type":"string","description":"RFC 3339 UTC with milliseconds"},"deterministic":{"type":"boolean"}}},"route":{"const":"/v1/code/jwt"},"version":{"type":"string"}}}}}}},"responseSchema":{"type":"json","example":{"ok":true,"data":{"alg":"HS256","kid":null,"typ":"JWT","time":{"expired":null,"age_seconds":274314578,"evaluated_at":"2026-09-28T00:00:00Z","not_yet_valid":null,"expires_in_seconds":null},"parts":3,"claims":{"aud":null,"exp":null,"iat":1516239022,"iss":null,"jti":null,"nbf":null,"sub":"1234567890"},"header":{"alg":"HS256","typ":"JWT"},"reason":null,"payload":{"iat":1516239022,"sub":"1234567890","name":"John Doe"},"warnings":[],"signature_bytes":32,"valid_structure":true,"signature_verified":false},"meta":{"price_usd":"0.05","disclaimer":"Factual output of a deterministic computation over public data. Provided as is, with no warranty of accuracy, completeness or availability. Not investment, financial, legal, tax, medical or any other professional advice, and not a recommendation. Verify before relying on it. Terms: https://api.duoleads.com/terms","request_id":"01K6B7Q4ZC8H3F2M9WXR5TYN0D","computed_at":"2026-09-28T12:00:00.000Z","deterministic":true},"route":"/v1/code/jwt","version":"1.0.0"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_4WBUYx4NnPRu5QZg5HkgB","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Decodes a JWT without signature verification, returning header, claims, payload, signature info, and computed time-claim analysis (expiry, not-before, remaining lifetime).","exampleAgentPrompt":"Can you decode this JWT for me and tell me if it's expired, what algorithm it uses, and show me all the claims? Here's the token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c","exampleUseCases":[{"title":"Debug an expired auth token","prompt":"This JWT keeps getting rejected by our API — can you decode it and tell me if it's expired, what the exp claim says, and how many seconds ago it expired? Token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzEyMyIsImV4cCI6MTY5MDAwMDAwMH0.abc123"},{"title":"Inspect claims before trusting a token","prompt":"I got this JWT from a third-party service and I want to see exactly what's in the header and payload — show me all the claims, the algorithm, the kid, and whether the nbf or exp claims look valid: eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImtleS0xIn0.eyJpc3MiOiJodHRwczovL2V4YW1wbGUuY29tIiwic3ViIjoiYWJjIiwibmJmIjoyMDAwMDAwMDAwfQ.sig"},{"title":"Evaluate token validity at a past timestamp","prompt":"Can you decode this JWT and check whether it would have been valid on January 1 2025 at midnight UTC? I want to know if it was expired or not-yet-valid at that specific moment. Token: eyJhbGciOiJIUzI1NiJ9.eyJleHAiOjE3MzU2ODk2MDB9.xyz"}],"resultDescription":"A JSON object containing the decoded JWT header (e.g. alg, typ, kid), full payload/claims (all registered and custom fields), number of parts, signature byte length, whether the structure is valid, any warnings (e.g. alg:none), and a computed time block showing whether exp has passed, whether nbf is still in the future, the age in seconds, and remaining lifetime — all evaluated against the supplied or current timestamp. The signature_verified field is always false since no verification is performed.","failureModes":["Token is malformed or missing a part — returns structural error indicating which part is absent","Invalid base64url encoding in header or payload — returns parse error","Algorithm is 'none' — reported as a warning in the warnings array","Token exceeds 8192 characters — rejected by input validation","Invalid 'at' timestamp format (not RFC 3339 or epoch seconds) — returns validation error","Network or service error — HTTP 5xx response"],"whenToPreferThis":"Use this endpoint when you need to inspect the contents of a JWT token quickly — to read claims, check expiry timing, or debug token structure — without needing to verify the signature. It is ideal for debugging, logging, and introspection workflows where the signature is already trusted or irrelevant. Do not use it as a security gate or trust decision; it explicitly does not verify signatures.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:46:16.667Z","isFirstParty":false,"canonicalSlug":"duo-data-utilities-jwt-decoder-0a5806b9"}