Jwt Decoder X402

by Br0ski777

233 downloads
Not rated
GitHub

About

Decode and inspect JWT tokens without verification. Extracts header, payload, claims, expiry, and signature algorithm. -- x402 micropayment API + MCP server for AI agents

Details

Author
Br0ski777
Downloads
233
Categories
Other

- Decode JWT tokens without signature verification
- Extract header, payload, claims, expiry, and algorithm
- Pay-per-call via x402 protocol (USDC on Base L2)
- No API key, signup, or rate-limit walls
- Part of the klymax402 marketplace of 100+ APIs
- Available as both MCP server and HTTP endpoint

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Jwt Decoder X402
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Add the server to your MCP client configuration (e.g., Claude Desktop, Cursor, ElizaOS) with the URL https://jwt-decoder.api.klymax402.com/mcp. Alternatively, use the HTTP endpoint POST /api/decode with a JSON body containing the token; an x402 payment challenge will be returned, and any x402-aware client (e.g., @x402/fetch, x402-agent-tools, ATXP) handles the payment cycle automatically.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "jwt decoder x402": {
            "jwt-decoder": {
                "url": "https://jwt-decoder-production.up.railway.app/mcp",
                "transport": "sse"
            }
        }
    }
}

McpServers

{
    "jwt-decoder": {
        "url": "https://jwt-decoder-production.up.railway.app/mcp",
        "transport": "sse"
    }
}

JWT Decoder API

MCP Server
x402
License: MIT

Decode and inspect JWT tokens without verification. Extracts header, payload, claims, expiry, and signature algorithm. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.

Part of the klymax402 marketplace -- 100 x402 micropayment APIs for AI agents, one wallet, USDC on Base.

Quickstart -- MCP

Add to your MCP client config (Claude Desktop, Cursor, ElizaOS, etc.):

{
  "mcpServers": {
    "jwt-decoder": {
      "url": "https://jwt-decoder.api.klymax402.com/mcp"
    }
  }
}

Quickstart -- HTTP (x402)

curl -X POST "https://jwt-decoder.api.klymax402.com/api/decode" \
  -H "Content-Type: application/json" \
  -d '{"token":"..."}'

-> 402 Payment Required, with an x402 payment challenge in the response body

Any x402-aware client (@x402/fetch, x402-agent-tools, ATXP) handles the 402 -> sign -> retry cycle automatically.

Tools

| Tool | Method | Path | Price | Description |
|---|---|---|---|---|
| security_decode_jwt | POST | /api/decode | $0.001 | Decode a JWT token without signature verification |

security_decode_jwt

Use this when you need to decode and inspect a JWT token without verifying its signature. Returns the full header, payload, and expiration status.

Parameters

| Name | Type | Required | Description |
|---|---|---|---|
| token | string | yes | The JWT token to decode (format: header.payload.signature) |

Example response:

{"header":{"alg":"RS256","typ":"JWT"},"payload":{"sub":"user123","exp":1720000000},"issuedAt":"2025-01-01T00:00:00Z","expiresAt":"2025-07-03T00:00:00Z","isExpired":false}

When to use: debugging authentication issues, inspecting token claims before API calls, or verifying token expiry. Use this BEFORE making authenticated requests to check if a token needs refreshing.

Not for: hashing data (use crypto_generate_hash), base64 encoding/decoding (use utility_encode_base64), password analysis (use security_check_password).

Example agent prompts

- "Decode and inspect a JWT token without verifying its signature"

Payment

- Protocol: x402 -- HTTP-native pay-per-call, no signup, no API key
- Network: Base L2 (eip155:8453)
- Asset: USDC
- Facilitator: Coinbase CDP (primary), PayAI (fallback)
- Also reachable via ATXP (OAuth-wrapped x402, RFC 9728 protected-resource metadata)

Part of klymax402

100 x402 micropayment APIs for AI agents -- one wallet, USDC on Base, zero signup.

- Catalog: https://klymax402.com/llms.txt
- Full API reference: https://klymax402.com/llms-full.txt
- Live stats: https://klymax402.com/stats

License

MIT

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.