JWT Decoder API

POST

Read claims, headers, and expiration details from any JWT.

JWT Decoder decodes JWT tokens to reveal header and payload information without performing signature verification.

Try it — live request, no key required

Request
POSTapi.apiverve.com/v1/jwtdecoder
Body
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "header": {
      "alg": "HS256",
      "typ": "JWT"
    },
    "payload": {
      "sub": "1234567890",
      "name": "John Doe",
      "iat": 1516239022
    },
    "signature": "SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c",
    "isExpired": false,
    "expiresAt": null,
    "issuedAt": "2018-01-18T01:30:22.000Z",
    "tokenAge": "2557 days",
    "algorithm": "HS256",
    "expiresIn": null,
    "notYetValid": false,
    "securityAnalysis": {
      "isUnsecured": false,
      "hasExpiration": false,
      "isLongLived": false,
      "issues": [
        "Token has no expiration (exp) claim — it never expires"
      ]
    },
    "warning": "This API only decodes JWT tokens. It does NOT verify signatures. Do not use for security validation."
  }
}

About the JWT Decoder API

Important: This API only decodes tokens and does NOT verify signatures. Not suitable for security validation or production authentication.

What people use it for

Token Debugging
Debug and inspect JWT tokens during development to view header and payload contents
Token Analysis
Analyze token structure and claims without performing cryptographic verification
Expiration Check
Check token expiration status and view expiration timestamps
Token Inspection
Inspect token contents for troubleshooting authentication issues

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

Other ways to use JWT Decoder

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the JWT Decoder API.

Read the docs →
Does this API verify cryptographic signatures?
No. JWT Decoder extracts the header and payload and returns the raw signature string without cryptographically validating it. Because signatures are not verified against a secret or public key, this tool is designed for debugging, inspection, and token analysis rather than production authentication.
How many token decodes does the Free plan cover?
The Free plan includes 200 credits per month, covering 100 token decodes at 2 credits per call. For higher debugging or logging volume, the Starter plan provides 100,000 decodes per month, which works out to about $0.30 per 1,000 calls.
Are token age and security analysis included on the Free plan?
No. The human-readable token age and structural security analysis are premium fields available only on paid plans. Free requests return the decoded header, payload claims, raw signature, and expiration flags, while Starter and higher plans unlock the security assessment.
What happens if a token does not have an expiration claim?
If a token omits an exp claim, the expiresAt and expiresIn fields return null. The response still provides all existing payload claims, header values, and other present timestamps like the issued-at time without failing.
What structural issues does the security analysis detect?
On paid plans, the security analysis inspects the token structure for common vulnerabilities, including unsigned tokens using alg:none, missing expiration claims, and tokens configured with an unusually long lifetime. It surfaces these flags directly in the response for quick debugging.

Ready to build with JWT Decoder? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs