POST /v1/crypto/jwt-decode

JWT decoder

Read the header and claims, see when it expires, and optionally verify the signature if you have the key.

Look inside a JSON web token now No key, no code — 1 credit either way.

curl -X POST "$DOATHING_API/v1/crypto/jwt-decode" \
  -H "x-api-key: $DOATHING_KEY" \
  -H "content-type: application/json" \
  -d '{"text": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ1MSJ9.sig", "key": "your-signing-key"}'

Read the header and claims, see when it expires, and optionally verify the signature if you have the key.

Decode a JWT header and payload, report expiry, and optionally verify HS256/384/512 signatures.

Input

Send either a text string or a file object. A file is decoded as UTF-8 and must be one of text/plain, text/markdown, text/html, text/csv.

Response

The result carries your remaining balance alongside it, so you can track spend without a second call.

{
  "header": {
    "alg": "HS256"
  },
  "payload": {
    "sub": "u1"
  },
  "expired": null,
  "signature_verified": true,
  "request_id": "37f01edb-0163-42a1-ac51-0acaef979800",
  "credits_remaining": 96
}

Cost

1 credit per call, whether it is run from the site or from the API — the credential differs, the price does not. A new account starts with 20 credits.

A rejected request still costs a credit: the authorizer decrements before the tool validates. A call rejected for a missing or invalid key is free.

Parameters

Generated from the endpoint’s own validation, so this is exactly what it accepts. A body field goes at the top level; an option goes inside options.

NameInTypeDefaultNotes
keybodystring