# Duo Data Utilities – JWT Decoder

> Duo Data Utilities – JWT Decoder is a paid API for AI agents from api.duoleads.com, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Decodes a JWT without signature verification, returning header, claims, payload, signature info, and computed time-claim analysis (expiry, not-before, remaining lifetime).

## Facts

- Endpoint: GET https://api.duoleads.com/v1/code/jwt?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/duo-data-utilities-jwt-decoder-0a5806b9
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_v_-iDFtlQ_4PgXX7cdX89

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability duo-data-utilities-jwt-decoder-0a5806b9
```

Example prompt: Can you decode this JWT for me and tell me if it's expired, what algorithm it uses, and show me all the claims? Here's the token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

## When to prefer this

Use this endpoint when you need to inspect the contents of a JWT token quickly — to read claims, check expiry timing, or debug token structure — without needing to verify the signature. It is ideal for debugging, logging, and introspection workflows where the signature is already trusted or irrelevant. Do not use it as a security gate or trust decision; it explicitly does not verify signatures.

## Known failure modes

- Token is malformed or missing a part — returns structural error indicating which part is absent
- Invalid base64url encoding in header or payload — returns parse error
- Algorithm is 'none' — reported as a warning in the warnings array
- Token exceeds 8192 characters — rejected by input validation
- Invalid 'at' timestamp format (not RFC 3339 or epoch seconds) — returns validation error
- Network or service error — HTTP 5xx response

## How this service works

Decode a JSON Web Token without verifying it: returns the header, the claims, the signature length and algorithm, and a computed view of the time claims — whether exp has passed, whether nbf is in the future, and the remaining lifetime in seconds against a supplied or current instant. Reports structural problems such as a missing part, invalid base64url or an alg of none. It does not and cannot verify the signature; do not use it to decide trust.

## Output

A JSON object containing the decoded JWT header (e.g. alg, typ, kid), full payload/claims (all registered and custom fields), number of parts, signature byte length, whether the structure is valid, any warnings (e.g. alg:none), and a computed time block showing whether exp has passed, whether nbf is still in the future, the age in seconds, and remaining lifetime — all evaluated against the supplied or current timestamp. The signature_verified field is always false since no verification is performed.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "token"
     ],
     "properties": {
      "at": {
       "type": "string",
       "maxLength": 64,
       "description": "Instant to evaluate exp/nbf against: RFC 3339 or epoch seconds. Default now."
      },
      "token": {
       "type": "string",
       "maxLength": 8192,
       "description": "The JWT to decode (not verified). At most 8192 characters."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "required": [
      "ok",
      "route",
      "version",
      "data",
      "meta"
     ],
     "properties": {
      "ok": {
       "const": true
      },
      "data": {
       "type": "object",
       "required": [
        "valid_structure",
        "header",
        "payload",
        "alg",
        "typ",
        "kid",
        "signature_bytes",
        "parts",
        "claims",
        "time",
        "signature_verified",
        "warnings",
        "reason"
       ],
       "properties": {
        "alg": {
         "type": [
          "string",
          "null"
         ]
        },
        "kid": {
         "type": [
          "string",
          "null"
         ]
        },
        "typ": {
         "type": [
          "string",
          "null"
         ]
        },
        "time": {
         "type": "object",
         "required": [
          "evaluated_at",
          "expired",
          "not_yet_valid",
          "expires_in_seconds",
          "age_seconds"
         ],
         "properties": {
          "expired": {
           "type": [
            "boolean",
            "null"
           ]
          },
          "age_seconds": {
           "type": [
            "integer",
            "null"
           ]
          },
          "evaluated_at": {
           "type": "string"
          },
          "not_yet_valid": {
           "type": [
            "boolean",
            "null"
           ]
          },
          "exp
… (truncated)
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "ok": true,
  "data": {
   "alg": "HS256",
   "kid": null,
   "typ": "JWT",
   "time": {
    "expired": null,
    "age_seconds": 274314578,
    "evaluated_at": "2026-09-28T00:00:00Z",
    "not_yet_valid": null,
    "expires_in_seconds": null
   },
   "parts": 3,
   "claims": {
    "aud": null,
    "exp": null,
    "iat": 1516239022,
    "iss": null,
    "jti": null,
    "nbf": null,
    "sub": "1234567890"
   },
   "header": {
    "alg": "HS256",
    "typ": "JWT"
   },
   "reason": null,
   "payload": {
    "iat": 1516239022,
    "sub": "1234567890",
    "name": "John Doe"
   },
   "warnings": [],
   "signature_bytes": 32,
   "valid_structure": true,
   "signature_verified": false
  },
  "meta": {
   "price_usd": "0.05",
   "disclaimer": "Factual output of a deterministic computation over public data. Provided as is, with no warranty of accuracy, completeness or availability. Not investment, financial, legal, tax, medical or any other professional advice, and not a recommendation. Verify before relying on it. Terms: https://api.duoleads.com/terms",
   "request_id": "01K6B7Q4ZC8H3F2M9WXR5TYN0D",
   "computed_at": "2026-09-28T12:00:00.000Z",
   "deterministic": true
  },
  "route": "/v1/code/jwt",
  "version": "1.0.0"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/duo-data-utilities-jwt-decoder-0a5806b9/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.duoleads.com](https://www.zero.xyz/host/api.duoleads.com/llms.txt)
