x402AgentTools

๐Ÿ”‘JWT Decoder

Decode a JSON Web Token's header and payload to readable JSON. Pure decoding: signatures are NOT verified and no secret is needed. Claims like exp and iat are rendered as dates.

Worked examples

Typical HS256 token

GET /api/v1/dev/jwt-decoder?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.dummy_signature_part

Result: { "sub": "1234567890", "name": "Jane Doe", "iat": 1700000000 }

Machine API (x402)

$0.001 / call

This tool is also a JSON API for AI agents. Requests without payment receive 402 Payment Required plus instructions; agents pay USDC on Base via the x402 protocol โ€” no accounts, no API keys.

GET /api/v1/dev/jwt-decoder?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.dummy_signature_part HTTP/1.1
Host: agenttools-hub.vercel.app

โ†’ 402 (payment required, instructions in headers)
โ†’ 200 (after X-PAYMENT header; JSON body below)

{
  "tool": "dev/jwt-decoder",
  "input": {"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.dummy_signature_part"},
  "result": { "value": null, "answer": "{
  "sub": "1234567890",
  "name": "Jane Doe",
  "iat": 1700000000
}" }
}

Agent docs: /llms.txt ยท OpenAPI spec ยท integration guide

About this tool

Paste any JWT to read its header (algorithm, type) and payload claims as formatted JSON. Decoding is pure base64url โ€” it reveals nothing about validity: a JWT is signed, not encrypted, and signature verification always requires the secret or public key.

JWT = base64url(header) + '.' + base64url(payload) + '.' + base64url(signature)

Frequently asked questions

Is decoding a JWT safe?

Yes โ€” anyone can decode any JWT because the parts are plain base64url. Never put secrets in a JWT payload for this reason.

Does this tool verify the signature?

No. Verification needs the signing key (HMAC secret or RSA/ECDSA public key) and should happen in your backend. This tool decodes only.

What does the exp claim mean?

Expiration time as a Unix timestamp. If present, it is rendered as an ISO date and flagged when already in the past.

Related tools