Skip to content
POST /api/v1/decode-jwt

JWT Decoder

Decode a JWT token and extract header, payload, and claims (no signature verification)

Parameters

name in type required description
token body string required JWT Token

Request

Send your key in the X-API-Key header. More languages and patterns live on the code examples page.

curl -s -X POST "https://apixies.io/api/v1/decode-jwt" \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0..."}'

Response

The result sits under data in the standard envelope. See the response format guide for errors and status codes.

returns

data.payload
The decoded claims, like sub, iat and exp.
data.header
Token header with the algorithm and type.
data.is_expired
True when exp is in the past, only present if exp is set.
data.expires_at
The exp claim as an ISO 8601 date.
data.issued_at
The iat claim as an ISO 8601 date.
data.signature
The raw signature segment, which isn't verified.
example response 200
{
    "status": "success",
    "http_code": 200,
    "code": "SUCCESS",
    "message": "JWT decoded successfully (signature NOT verified)",
    "data": {
        "header": {
            "alg": "HS256",
            "typ": "JWT"
        },
        "payload": {
            "sub": "1234567890",
            "name": "John Doe",
            "iat": 1700000000,
            "nbf": 1700000000,
            "exp": 1700003600
        },
        "signature": "_WnuDIVcRDLpjyOIYZ37cWLMU6OEahm-9JK4UwPD8Ns",
        "expires_at": "2023-11-14T23:13:20+00:00",
        "is_expired": true,
        "issued_at": "2023-11-14T22:13:20+00:00",
        "not_before": "2023-11-14T22:13:20+00:00",
        "decoded_at": "2026-09-18T12:00:00+00:00"
    }
}

Authentication and limits

This endpoint needs an API key. Use the sandbox ("try it" above) to test it without registering. See the authentication guide for details.

Standard rate limits apply to this endpoint.

Common use cases

Debug authentication flows

Quickly inspect JWT tokens during development to verify claims, expiration times, and payload structure without writing custom parsing code.

Security audit logging

Decode and log JWT claims in your API gateway for audit trails. Extract user IDs, roles, and permissions from tokens passing through your system.

Token validation in pipelines

Integrate JWT decoding into CI/CD pipelines to verify that test tokens have the correct structure and claims before running integration tests.

More documentation

Get a free API key

A temporary key takes one click and no signup. Register and you get 75 requests/day. Free tier is for development & small projects.

cookies

We use analytics cookies to see how the site gets used. Nothing loads until you accept. Privacy policy