81trust / 100

Dev Jwt Decoder

by AgentTools in Developer tools

x402 APIPassing, checked 54 min ago

Decode a JSON Web Token's header and payload to readable JSON. Pure decoding: signatures are NOT verified and no secret is needed. Claims like exp and iat are rendered as dates. Use this when an agent needs to decode header and payload — no verification.

GET https://agenttools-hub.vercel.app/api/v1/dev/jwt-decoder

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
139 ms typical, 139 ms slowest 5%
Last check
54 min ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://agenttools-hub.vercel.app/api/v1/dev/jwt-decoder?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.dummy_signature_part"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fagenttools-hub.vercel.app%2Fapi%2Fv1%2Fdev%2Fjwt-decoder
const res = await pay("https://agenttools-hub.vercel.app/api/v1/dev/jwt-decoder?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.dummy_signature_part");
console.log(await res.json());

Example input

{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzAwMDAwMDAwfQ.dummy_signature_part"
}

Example output

{
  "result": {
    "answer": "{\n  \"sub\": \"1234567890\",\n  \"name\": \"Jane Doe\",\n  \"iat\": 1700000000\n}",
    "answerLabel": "Payload claims",
    "details": [
      {
        "label": "Algorithm",
        "value": "HS256"
      },
      {
        "label": "Type",
        "value": "JWT"
      },
      {
        "label": "Signature",
        "value": "present (20 chars) — NOT verified"
      },
      {
        "label": "Time claim",
        "value": "iat: 2023-11-14T22:13:20.000Z"
      }
    ],
    "steps": [
      "Split token on dots",
      "Base64url-decode header and payload",
      "Parse both as JSON (signature left untouched)"
    ],
    "value": null
  },
  "tool": "jwt-decoder"
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
54 min agoPassed402144 ms$0.003
6 h agoPassed402139 ms$0.003