JWT toolkit
Decode and verify a JWT in one pass - see the payload and check the signature.
3 tools run server-side in one request. You pay once, settle once, and get a single response - no orchestration, no per-step payments, and a partial-success envelope if any step fails. USDC over x402 on any supported chain.
When to use this pack
An agent debugging authentication needs to both decode a JWT (see claims, expiry, issuer) and verify the signature. Two operations that always go together, bundled into one payment.
Tools in this pack
All 3 run inside the single $0.003 call above. Each is also callable on its own if you only need one part.
- JWT decode POST /api/jwt-decode Decode a JWT without verification: header (algorithm), payload claims (subject, issuer, expiration), expiry status, and time remaining. (Decoding only - signatures are NOT verified.)
- JWT verify (HMAC) POST /api/jwt-verify Verify an HS256/384/512 JWT signature against a secret and check expiry. Returns valid + decoded payload. (HMAC algorithms only.)
- JWT sign POST /api/jwt-sign Mint a signed JSON Web Token (HMAC: HS256 default, HS384, HS512) from a payload + secret. Pairs with jwt-decode/jwt-verify to complete the trio. Deterministic - same payload, secret, and alg always produce the same token.
Bought one at a time, these 3 tools cost $0.003 together; the pack is that sum less a 10% bundle discount, rounded up to the $0.001 settlement floor, which is $0.003.
Workflow
- Call jwt-decode to extract the header (algorithm, type) and payload (claims, expiry) without verification.
- Call jwt-verify with the token and secret='test' to check whether the signature is valid.
- Call jwt-sign with the decoded claims and secret='test' to re-issue a fresh token - the round-trip you need when rotating a signing secret, reproducing a token in a test fixture, or confirming the decode captured every claim.
Arguments
| Name | Required | Description | Example |
|---|---|---|---|
token | yes | JWT token string | eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ0ZXN0In0.xxx |
What one call returns
A JSON object with pack, args, steps, summary; steps holds one entry per tool (jwt-decode, jwt-verify, jwt-sign), each with its own result or error. Full example on the API page.
Call it directly
Any x402 client pays the 402 and gets the whole workflow back in one response. With the agent402-client SDK (npm i agent402-client, an ES module):
import { Agent402 } from "agent402-client";
// payFetch: an x402-wrapped fetch your wallet signs (@x402/fetch).
// Tools on the free tier need no options: new Agent402() pays them by proof-of-work.
// an existing prepaid credits key also works: new Agent402({ creditsKey })
const client = new Agent402({ fetch: payFetch });
const result = await client.call("skill-jwt-toolkit", {"token":"eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ0ZXN0In0.xxx"});
Run it in Claude
claude mcp add agent402 -s user -- npx -y agent402-mcp@latest
Then paste this prompt into Claude:
Analyze this JWT using Agent402's jwt-toolkit skill pack: eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ0ZXN0In0.xxx. (1) Decode it to see the claims, (2) verify the signature with secret='test', (3) re-sign the claims with jwt-sign (secret='test'). Report the payload, verification result, and the re-issued token.