Overview
Important: This API only decodes tokens and does NOT verify signatures. Not suitable for security validation or production authentication.
Live Test JWT Decoder Skill Skill →
The tool
Once your client is connected to the VerveKit server, this appears in its tool list as JWTDecoderSkill. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.
{
"name": "JWTDecoderSkill",
"arguments": {
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}
}You do not name the tool yourself; the model picks it. Asking about eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c in the terms this skill covers is enough for it to reach for JWTDecoderSkill on its own — naming it explicitly also works, and is the way to force the call.
Connecting
One server URL covers every skill in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.
{
"mcpServers": {
"vervekit": {
"url": "https://api.vervekit.com/v1/mcp"
}
}
}https://api.vervekit.com/v1/mcpPer-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.
Arguments
These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.
| Argument | Type | Description |
|---|---|---|
tokenRequired | string | JWT token to decode |
What the model gets back
The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.
{
"status": "ok",
"error": null,
"data": {
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
},
"signature": "SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c",
"isExpired": false,
"expiresAt": null,
"issuedAt": "2018-01-18T01:30:22.000Z",
"tokenAge": "2557 days",
"algorithm": "HS256",
"expiresIn": null,
"notYetValid": false,
"securityAnalysis": {
"isUnsecured": false,
"hasExpiration": false,
"isLongLived": false,
"issues": [
"Token has no expiration (exp) claim — it never expires"
]
},
"warning": "This API only decodes JWT tokens. It does NOT verify signatures. Do not use for security validation."
}
}
Response fields
Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.
| Field | Type | Example | Description |
|---|---|---|---|
header | object | {…} | Decoded JWT header, typically containing the signing algorithm and token type |
header.alg | string | HS256 | |
header.typ | string | JWT | |
payload | object | {…} | Decoded JWT payload containing the token's claims (e.g. subject, issuer, expiration, and any custom claims) |
payload.sub | string | 1234567890 | |
payload.name | string | John Doe | |
payload.iat | number | 1516239022 | |
signature | string | SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c | Raw, unverified signature segment of the token (the third dot-separated part); not cryptographically validated by this API |
isExpired | boolean | false | Whether the token's expiration (exp claim) is in the past |
expiresAt | object | null | ISO timestamp of when the token expires (from the exp claim); null if there is no exp claim |
issuedAt | string | 2018-01-18T01:30:22.000Z | ISO timestamp of when the token was issued (from iat claim) |
tokenAgePremium | string | 2557 days | Human-readable age of the token |
algorithm | string | HS256 | Signing algorithm declared in the token header (alg) |
expiresIn | object | null | Seconds until the token expires; negative once expired, null if there is no exp claim |
notYetValid | boolean | false | Whether the token's not-before (nbf) claim is still in the future |
securityAnalysisPremium | object | {…} | Structural security assessment of the token: unsigned (alg:none) detection, missing expiration, over-long lifetime, and a list of issues. Does not verify the signature. |
securityAnalysis.isUnsecuredPremium | boolean | false | |
securityAnalysis.hasExpirationPremium | boolean | false | |
securityAnalysis.isLongLivedPremium | boolean | false | |
securityAnalysis.issuesPremium | array | ["Token has no expiration (exp) claim — it never expires"] | |
warning | string | This API only decodes JWT tokens. It does NOT verify signatures. Do not use for security validation. | Reminder that this API only decodes the token and does not verify its signature |
Failure modes
Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.
| Status | What it means |
|---|---|
400 / 422 | The arguments did not validate. The message names the offending one. |
401 | The OAuth session is invalid or expired — reconnect the server. |
403 | Blocked by a key restriction or an IP allow-list. Never a bad identity. |
404 | This skill is not part of VerveKit. Check the catalog. |
429 | Out of credits, or a brief rate limit. The message tells them apart. |
A call costs 2 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.
Use cases
- Token Debugging
- Debug and inspect JWT tokens during development to view header and payload contents
- Token Analysis
- Analyze token structure and claims without performing cryptographic verification
- Expiration Check
- Check token expiration status and view expiration timestamps
- Token Inspection
- Inspect token contents for troubleshooting authentication issues
Other ways to use JWT Decoder Skill
Set up JWT Decoder Skill on VerveKit, or reach the same source a different way. Your VerveKit account and credits work on all of them — one key, one balance.
Related
More in Data Conversion: