About this endpoint
What it does
Decodes a JWT without verifying its signature and returns the header, payload, algorithm, readable claims, and expiry status. The request body contains the JWT as a token string.
Request Body
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
| token | String | Yes | The JWT to decode as three dot-separated base64url segments. |
Response
Returns a JSON object with the decoded header and payload of the token, its declared algorithm, and expiry details. The signature segment is returned but never verified.
| Field | Type | Description |
|---|---|---|
| header | Object | The decoded JWT header (e.g. alg, typ). |
| payload | Object | The decoded JWT payload/claims, as submitted in the token. |
| algorithm | String | The signing algorithm declared in the header (e.g. HS256). |
| type | String or null | The token type declared in the header (typ), if present. |
| signature | String | The raw (unverified) signature segment of the token. |
| readable_claims | Object | Standard registered claims (iat, nbf, exp) converted to readable ISO timestamps, when present in the payload. |
| expired | Boolean or null | Whether the token's exp claim has passed. null if no exp claim is present. |
| seconds_until_expiry | Integer or null | Seconds remaining until expiry. Negative if already expired, null if no exp claim is present. |
| verified | Boolean | Always false. Signature verification is never performed. |
| note | String | Reminder that the signature is not verified and no secret is used. |



