utilpeek: verify a JWT signature and claims with a secret, a PEM public key or a JWK Set
verify_jwtutilpeek: Verify a JWT signature and claims. Returns valid true or false for a JWT checked with PyJWT against one key (HMAC secret, PEM public key or JWK Set), with a reason: bad signature, expired, wrong audience or issuer, algorithm not allowed. Algorithm none is refused; the key type fixes the algorithm family. Input: token and exactly one of secret, public_key or jwks; optional algorithms, audience, issuer, leeway_seconds. Pure computation, no network; secrets and keys are not echoed. A failed check is a normal charged result (valid false). No JWKS URL fetch: send the key set. Malformed input is a 422 (not charged). Typically under 0.1 s. Price: USD 0.001. Free: 10 utilpeek calls per IP per UTC day. Tanod does not log or store the submitted text; it is processed in memory for this answer. Docs: https://tanod.dev/learn/jwt-decode-verify-api.html
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| jwks | No | JWK Set object {"keys": [...]} (asymmetric keys; oct keys are ignored). The key is picked by the token kid. | |
| token | Yes | Compact JWT to verify. | |
| issuer | No | Required iss. | |
| secret | No | HMAC secret (HS256/384/512). | |
| audience | No | Required aud (a string, or a list of which one must match). | |
| algorithms | No | Allow-list that narrows the default for the key type; none is refused. | |
| public_key | No | PEM public key (RS*, PS*, ES*, EdDSA). | |
| leeway_seconds | No | Clock skew allowed for exp, nbf and iat (0-300). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| alg | No | ||
| kid | No | ||
| note | No | ||
| error | No | Only on an error result: an object {code, message}, or the reason string of an x402 PaymentRequired object. | |
| valid | No | ||
| detail | No | ||
| header | No | ||
| reason | No | ||
| payload | No | ||
| key_source | No | ||
| leeway_seconds | No |