81trust / 100

Jwt Inspector Decode

by NetIntel in Search & web

x402 APIPassing, checked 44 min ago

Decode and inspect any JWT token — extracts header algorithm, payload claims, expiry status, issued-at time, audience, issuer, and subject without requiring the secret — so agents can debug auth issues, check token expiry, and extract identity claims from tokens in pipelines.

GET https://netintel.dev/jwt-inspector/decode

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
178 ms typical, 178 ms slowest 5%
Last check
44 min ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://netintel.dev/jwt-inspector/decode?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fnetintel.dev%2Fjwt-inspector%2Fdecode
const res = await pay("https://netintel.dev/jwt-inspector/decode?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c");
console.log(await res.json());

Example input

{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}

Example output

{
  "findings": [
    {
      "detail": "JWT has no exp claim — token never expires",
      "impact": -20,
      "label": "No expiry claim",
      "rule": "no_expiry_claim"
    }
  ],
  "grade": "B",
  "header": {
    "algorithm": "HS256",
    "key_id": null,
    "token_type": "JWT"
  },
  "human_expiry": null,
  "is_expired": null,
  "payload": {
    "audience": null,
    "custom_claims": {
      "name": "John Doe"
    },
    "expires_at": null,
    "expires_at_unix": null,
    "issued_at": "2018-01-18T01:30:22.000Z",
    "issued_at_unix": 1516239022,
    "issuer": null,
    "jwt_id": null,
    "not_before": null,
    "subject": "1234567890"
  },
  "score": 80,
  "seconds_until_expiry": null,
  "security_flags": [
    "no_expiry"
  ],
  "signature_hex": "49f94ac7044948c78a285d904f87f0a4c7897f7e8f3a4eb2255fda750b2cc397",
  "signature_present": true,
  "valid_structure": true
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
44 min agoPassed402182 ms$0.005
6 h agoPassed402178 ms$0.005