Module

jwt

Decodes a JWT segment without verifying the signature. Verification, where this SDK needs it, stays in Auth#verify (the one place that actually checks a signature against a JWKS) — this module is only for reading claims out of a token whose signature is either irrelevant to the caller (it'll be verified server-side when the request lands) or already been checked elsewhere.

Shared by Auth (decodes tokens obtained from OAuth flows) and InsightsService (a script-scoped client decodes its own token to read its sourceId/permissions claims). Buffer is used deliberately over atob — it's UTF-8-aware (claims like a tenant's display name can contain non-ASCII characters) and, confirmed via a live check, is available as a global in Deno as well as Node, so this stays usable from either runtime.

View Source jwt.js, line 1