{
  "company": "Doormat Capital",
  "tool": "jwtcheck — JWT decoder and signature verifier",
  "for_whom": "Anyone debugging auth: backend/API developers, anyone integrating an OAuth/OIDC provider, agents that need to inspect or validate a bearer token programmatically.",
  "endpoints": {
    "GET/POST /decode": "FREE — decodes header + payload, reports exp/iat/nbf as readable times, flags issues (alg:none, expired, missing exp). No signature check, no network call.",
    "GET/POST /verify": "paid, 0.02 USDC per call — cryptographically verifies the signature. HS256/384/512 needs 'secret'; RS256/384/512 and ES256/384 need 'jwks' (a JWKS URL) and are matched by 'kid'."
  },
  "usage_examples": {
    "decode": "GET /decode?token=<jwt>",
    "verify_hmac": "GET /verify?token=<jwt>&secret=<shared-secret>",
    "verify_jwks": "GET /verify?token=<jwt>&jwks=https://issuer.example.com/.well-known/jwks.json"
  },
  "payment_method_for_verify": "X-PAYMENT-TX header: send USDC on Base to 0x202B73254C28fA012BD11ff50425D94534b95594, then call /verify with header 'X-PAYMENT-TX: <your tx hash>' -- or, from a browser with no way to set a header, add '&tx=<your tx hash>' to the URL instead. Verified read-only via Base's public RPC, no facilitator, no account.",
  "pay_to": "0x202B73254C28fA012BD11ff50425D94534b95594",
  "network": "base",
  "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
  "other_products": {
    "urls": [
      "https://payverify.sebastiaan-ba3.workers.dev",
      "https://x402lint.sebastiaan-ba3.workers.dev",
      "https://mailcheck.sebastiaan-ba3.workers.dev",
      "https://metacheck.sebastiaan-ba3.workers.dev",
      "https://secheaders.sebastiaan-ba3.workers.dev",
      "https://crawlercheck.sebastiaan-ba3.workers.dev"
    ]
  },
  "contact": "t.me/doormatcapitalbot"
}