The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the JWT Decoder API listing page.
Decode and inspect JWT tokens without verification. Extracts header, payload, claims, expiry, and signature algorithm. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.
Part of the klymax402 marketplace -- 100 x402 micropayment APIs for AI agents, one wallet, USDC on Base.
Add to your MCP client config (Claude Desktop, Cursor, ElizaOS, etc.):
Any x402-aware client (@x402/fetch, x402-agent-tools, ATXP) handles the 402 -> sign -> retry cycle automatically.
| Tool | Method | Path | Price | Description |
|---|---|---|---|---|
security_decode_jwt | POST | /api/decode | $0.003 | Decode a JWT token without signature verification |
security_decode_jwtUse this when you need to decode and inspect a JWT token without verifying its signature. Returns the full header, payload, and expiration status.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
token | string | yes | The JWT token to decode (format: header.payload.signature) |
Example response:
When to use: debugging authentication issues, inspecting token claims before API calls, or verifying token expiry. Use this BEFORE making authenticated requests to check if a token needs refreshing.
Not for: hashing data (use crypto_generate_hash), base64 encoding/decoding (use utility_encode_base64), password analysis (use security_check_password).
eip155:8453)100 x402 micropayment APIs for AI agents -- one wallet, USDC on Base, zero signup.
MIT