Skip to main content

jwt_decode

Decode a JWT (JSON Web Token) and return the header and payload as JSON objects. The signature is never verified — any well-formed three-part token is accepted regardless of which secret was used or whether the token has expired.

Useful for inspecting token structure, extracting claims for debugging, or reading tokens received from third-party services when you do not have the signing secret.

Parameters​

ParameterTypeRequiredDescription
tokenstringYesThe JWT string to decode. Must have three dot-separated base64url-encoded parts (header.payload.signature).

Response​

FieldTypeDescription
headerobjectThe decoded JWT header as JSON.
payloadobjectThe decoded JWT payload as JSON.

Example​

{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}

Result:

{
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}
}

Errors​

Each failure carries a precise code in the response. Argument-schema and server errors are JSON-RPC protocol errors; a rejected value is returned as a tool result with isError: true (so the agent can read the code and self-correct).

CodeWhenDelivered as
invalid_argumentsThe token field is missing or not a string.protocol error (invalid_params)
jwt_malformedThe token does not have three dot-separated parts (header.payload.signature).tool error (isError)
jwt_invalid_base64urlA token part is not valid base64url.tool error (isError)
jwt_invalid_jsonA token part does not decode to valid JSON.tool error (isError)
internal_errorAn unexpected server error.protocol error (internal_error)

Notes​

  • Signature is ignored. jwt_decode is a base64url-split and JSON-parse operation — it never touches the signature. Use jwt_verify_hs256, jwt_verify_hs384, or jwt_verify_hs512 if you need to check the signature.
  • Works on expired tokens. Because no claims are validated, jwt_decode is useful for inspecting tokens that can no longer be verified (e.g. tokens from old sessions stored in logs).
  • Only HMAC-signed tokens are supported by the sign and verify tools. However, jwt_decode accepts any JWT regardless of the algorithm in the header — RSA and ECDSA tokens can be decoded for inspection.