analyze_jwt
Decode a JSON Web Token to inspect its algorithm, claims, and expiry, and flag suspicious header parameters like alg:none or jku. Signatures are not verified, so treat all claims as untrusted.
Instructions
Decode a JWT and report its algorithm, claims, expiry and suspicious header parameters (alg:none, jku, jwk, x5u). The signature is NOT verified -- this server has no key and will not pretend otherwise, so treat every claim as untrusted. Local only: nothing is sent anywhere. Cost: free, no quota, instant.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| token | Yes | The JWT, with or without a Bearer prefix. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| note | No | The signature is NOT verified: this server does not hold the key. Treat every claim as attacker-controlled input. | |
| header | No | ||
| expired | No | ||
| payload | No | ||
| findings | No | ||
| algorithm | No | ||
| issued_at | No | ||
| expires_at | No | ||
| not_before | No | ||
| valid_structure | Yes | ||
| signature_present | No | ||
| signature_length_bytes | No |