sseMITupdated 1mo ago
Decode and inspect JWT tokens without verification. Extracts header, payload, claims, expiry, and signature algorithm. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.
What can you do with JWT Decoder API?
JWT Decoder API
Decode and inspect JWT tokens without verification. Extracts header, payload, claims, expiry, and signature algorithm. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.
Part of the klymax402 marketplace -- 100 x402 micropayment APIs for AI agents, one wallet, USDC on Base.
Quickstart -- MCP
Add to your MCP client config (Claude Desktop, Cursor, ElizaOS, etc.):
{
"mcpServers": {
"jwt-decoder": {
"url": "https://jwt-decoder.api.klymax402.com/mcp"
}
}
}
Quickstart -- HTTP (x402)
curl -X POST "https://jwt-decoder.api.klymax402.com/api/decode" \
-H "Content-Type: application/json" \
-d '{"token":"..."}'
# -> 402 Payment Required, with an x402 payment challenge in the response body
Any x402-aware client (@x402/fetch, x402-agent-tools, ATXP) handles the 402 -> sign -> retry cycle automatically.
Tools
| Tool | Method | Path | Price | Description |
|---|---|---|---|---|
security_decode_jwt |
POST | /api/decode |
$0.003 | Decode a JWT token without signature verification |
security_decode_jwt
Use this when you need to decode and inspect a JWT token without verifying its signature. Returns the full header, payload, and expiration status.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
token |
string | yes | The JWT token to decode (format: header.payload.signature) |
Example response:
{"header":{"alg":"RS256","typ":"JWT"},"payload":{"sub":"user123","exp":1720000000},"issuedAt":"2025-01-01T00:00:00Z","expiresAt":"2025-07-03T00:00:00Z","isExpired":false}
When to use: debugging authentication issues, inspecting token claims before API calls, or verifying token expiry. Use this BEFORE making authenticated requests to check if a token needs refreshing.
Not for: hashing data (use crypto_generate_hash), base64 encoding/decoding (use utility_encode_base64), password analysis (use security_check_password).
Example agent prompts
- "Decode and inspect a JWT token without verifying its signature"
Payment
- Protocol: x402 -- HTTP-native pay-per-call, no signup, no API key
- Network: Base L2 (
eip155:8453) - Asset: USDC
- Facilitator: Coinbase CDP (primary), PayAI (fallback)
- Also reachable via ATXP (OAuth-wrapped x402, RFC 9728 protected-resource metadata)
Part of klymax402
100 x402 micropayment APIs for AI agents -- one wallet, USDC on Base, zero signup.
- Catalog: https://klymax402.com/llms.txt
- Full API reference: https://klymax402.com/llms-full.txt
- Live stats: https://klymax402.com/stats
License
MIT
Install
Add JWT Decoder API to your client. Pick the one you use.
claude mcp add --transport sse jwt-decoder-api https://jwt-decoder.api.klymax402.com/mcpcodex mcp add jwt-decoder-api --url https://jwt-decoder.api.klymax402.com/mcp{
"mcpServers": {
"jwt-decoder-api": {
"url": "https://jwt-decoder.api.klymax402.com/mcp"
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
{
"servers": {
"jwt-decoder-api": {
"type": "sse",
"url": "https://jwt-decoder.api.klymax402.com/mcp"
}
}
}Add to `.vscode/mcp.json` in your workspace.
{
"mcpServers": {
"jwt-decoder-api": {
"url": "https://jwt-decoder.api.klymax402.com/mcp"
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"jwt-decoder-api": {
"serverUrl": "https://jwt-decoder.api.klymax402.com/mcp"
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
1 tool
JWT Decoder API exposes one tool to a connected agent.
- security_decode_jwt
- POST
Score
76 / 100
Good
- Documentation22/25
- Maintenance25/25
- Trust13/20
- Capability4/15
- Install experience12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 25 days ago
- Has a release history
- Repository is not archived
- Licensed MIT
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 1 tool(s) documented
- Provides prompt templates
- Provides resources
- 6 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Version history
| Versions | Published |
|---|---|
| 1.1.0Latest | May 16, 2026 |
| 1.0.2 | Apr 23, 2026 |
| 1.0.1 | Apr 13, 2026 |
| 1.0.0 | Apr 13, 2026 |