81trust / 100
Jwt Inspector Decode
by NetIntel in Search & web
x402 APIPassing, checked 44 min ago
Decode and inspect any JWT token — extracts header algorithm, payload claims, expiry status, issued-at time, audience, issuer, and subject without requiring the secret — so agents can debug auth issues, check token expiry, and extract identity claims from tokens in pipelines.
GET https://netintel.dev/jwt-inspector/decode
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 178 ms typical, 178 ms slowest 5%
- Last check
- 44 min ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X GET "https://netintel.dev/jwt-inspector/decode?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fnetintel.dev%2Fjwt-inspector%2Fdecode
const res = await pay("https://netintel.dev/jwt-inspector/decode?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c");
console.log(await res.json());Example input
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}Example output
{
"findings": [
{
"detail": "JWT has no exp claim — token never expires",
"impact": -20,
"label": "No expiry claim",
"rule": "no_expiry_claim"
}
],
"grade": "B",
"header": {
"algorithm": "HS256",
"key_id": null,
"token_type": "JWT"
},
"human_expiry": null,
"is_expired": null,
"payload": {
"audience": null,
"custom_claims": {
"name": "John Doe"
},
"expires_at": null,
"expires_at_unix": null,
"issued_at": "2018-01-18T01:30:22.000Z",
"issued_at_unix": 1516239022,
"issuer": null,
"jwt_id": null,
"not_before": null,
"subject": "1234567890"
},
"score": 80,
"seconds_until_expiry": null,
"security_flags": [
"no_expiry"
],
"signature_hex": "49f94ac7044948c78a285d904f87f0a4c7897f7e8f3a4eb2255fda750b2cc397",
"signature_present": true,
"valid_structure": true
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 44 min ago | Passed | 402 | 182 ms | $0.005 |
| 6 h ago | Passed | 402 | 178 ms | $0.005 |