security $0.0005 / call
Secret Scan
Detect five families of credential patterns with fully masked findings.
security.secret-scansecurity.jwt-inspect · v1.0.0
Decode untrusted JWT claims and optionally compare timestamps; never verifies a signature.
{
"token": "eyJhbGciOiJub25lIn0.eyJzdWIiOiJkZW1vIn0."
}{
"header": {
"alg": "none"
},
"claims": {
"sub": "demo"
},
"signatureVerified": false,
"expired": null,
"notYetValid": null,
"warnings": [
"Unsigned algorithm declared."
],
"scope": "Decodes untrusted claims only. No signature, issuer, audience or authorization verification."
}Generated from the actual handler using this example input; this is a preview, not a paid API call. Paid responses wrap the result with a receipt and recovery expiry.
Add credits in the workspace and keep your API key in private environment storage. Use the same request ID and exact body to recover a lost response within ten minutes.
// Node.js 22+. Read the key from your private environment.
const requestId = Date.now() + '_' + crypto.randomUUID();
const response = await fetch('https://agent-utilities.agent-utilities.workers.dev/v1/tools/security.jwt-inspect', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Authorization': 'Bearer ' + process.env.AGENT_UTILITIES_API_KEY,
'Idempotency-Key': requestId
},
body: JSON.stringify({
"token": "eyJhbGciOiJub25lIn0.eyJzdWIiOiJkZW1vIn0."
})
});
const data = await response.json();
if (!response.ok) throw new Error(data.error?.message ?? 'Request failed');
console.log(data);
// On response loss, retry this SAME requestId, tool and body.
// Do not rerun the line that generates requestId for a retry.{
"type": "object",
"properties": {
"token": {
"type": "string",
"minLength": 1,
"maxLength": 20000
},
"atUnixSeconds": {
"type": "integer",
"minimum": 0
}
},
"required": [
"token"
],
"additionalProperties": false
}{
"type": "object",
"properties": {
"header": {
"type": "object"
},
"claims": {
"type": "object"
},
"signatureVerified": {
"const": false
},
"expired": {
"type": [
"boolean",
"null"
]
},
"notYetValid": {
"type": [
"boolean",
"null"
]
},
"warnings": {
"type": "array",
"items": {
"type": "string"
}
},
"scope": {
"type": "string"
}
},
"required": [
"header",
"claims",
"signatureVerified",
"expired",
"notYetValid",
"warnings",
"scope"
],
"additionalProperties": false
}Prices are experimental. The service currently allows 1,000 new calls per day across all accounts. Failed operations return reserved credits. This tool may process sensitive content; use sanitized samples when possible. Successful results are encrypted for ten-minute retry recovery. Review data handling and service limits.
security $0.0005 / call
Detect five families of credential patterns with fully masked findings.
security.secret-scansecurity $0.0005 / call
Replace detected credential patterns with redaction markers.
security.secret-redactsecurity $0.0005 / call
Parse a supplied Content Security Policy and flag selected risky or missing directives.
security.csp-audit