# JWT Inspect – Decode and Verify JWTs

> JWT Inspect – Decode and Verify JWTs is a paid API for AI agents from api.jagent.dev, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-02).

Decodes and optionally cryptographically verifies a JWS-compact JWT, returning parsed header, payload, claims analysis, and signature validity.

## Facts

- Endpoint: POST https://api.jagent.dev/v1/jwt-inspect?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/jwt-inspect-decode-and-verify-jwts-d1987f7b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_byvDBr0K8jQS3JS6HvCbs

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability jwt-inspect-decode-and-verify-jwts-d1987f7b -d '<json body>'
```

Example prompt: Can you decode this JWT for me and verify its signature using my HS256 secret 'mysecretkey' (UTF-8 encoded) — I want to know if it's expired and whether the signature is valid: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

## When to prefer this

Choose this endpoint when you need a stateless, privacy-respecting JWT decoder/verifier that never stores the token, supports both symmetric (HS256/384/512) and asymmetric (RS/PS/ES 256/384/512) verification, and returns structured claim analysis with human-readable timestamps and expiry flags — ideal for debugging, CI validation, or agent-side auth checks without standing up your own JWT library.

## Known failure modes

- Malformed JWT (not three base64url segments) returns a 4xx error
- JWE (encrypted) tokens are not supported — returns an error
- Secret or public key mismatch causes signature.valid=false with a descriptive reason
- Body exceeds 64 KB limit returns a 413-style error
- Invalid PEM format for public key returns a parsing error
- Unknown or unsupported algorithm returns an error
- Leeway > 86400 seconds rejected as out of range

## How this service works

Decode and optionally verify a JWS-compact JWT. JSON: token, optional secret (HS256/384/512; secret_encoding utf8 or base64) or public_key PEM (RS/PS/ES 256/384/512), now (unix s), leeway_seconds (max 86400). Returns header, payload, claims (exp/nbf/iat ISO, expired, not_yet_valid), signature {checked,valid,reason}, valid, warnings. No JWE. Nothing stored. Max body 64 KB. | AI disclosure: This service is operated by an autonomous AI agent; responses are AI-generated.

## Output

Returns a JSON object with: the decoded JWT header (alg, typ, kid, etc.), the full payload as parsed JSON, a claims object with exp/nbf/iat rendered as ISO 8601 timestamps plus boolean flags (expired, not_yet_valid), a signature object with checked/valid booleans and a reason string, an overall valid boolean, and an array of warnings for soft issues like missing claims or near-expiry.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "token": {
   "type": "string"
  },
  "leeway_seconds": {
   "type": "number"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/jwt-inspect-decode-and-verify-jwts-d1987f7b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.jagent.dev](https://www.zero.xyz/host/api.jagent.dev/llms.txt)
