JWT Tools

io.github.basitalisandhuv0.1.1Updated Oct 5, 2026

Decode JWTs without verifying, flag risky algorithms and claims, verify HS256 or RS256 with a key.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Decode, inspect and verify JSON Web Tokens, and mint test tokens, using a local stdio server.

What it does
Provides three tools: decode_jwt reads a token's header and payload without verifying it, returning ISO timestamps and findings such as alg none or missing, empty signature, jku/x5u/jwk headers, expired or not-yet-valid times, missing standard claims, long lifetimes, millisecond timestamps and secret-like claim names. verify_jwt checks an HS256/384/512 or RS256/384/512 signature against a supplied key for exactly the given algorithm, then validates exp, nbf, aud and iss. sign_test_jwt signs a claims object for test fixtures.
When to use it
Useful when debugging authentication flows, inspecting a token's claims and expiry, checking whether a token is signed with a risky algorithm, or generating throwaway tokens for tests. It is a local developer utility rather than a production verification service.
Requirements
Runs locally over stdio; no network, files or accounts. Install via npx with the pinned package version, or from a checkout with Node.js after npm install and npm run build. Docker image ghcr.io/basitalisandhu/mcp-jwt-tools:0.1.1 is also published. Keys are supplied per call as tool arguments.
Before you install
verify_jwt and sign_test_jwt take a key argument, so real secrets or private keys may pass through the assistant and the model context; the README states keys are used for the one call and not stored. decode_jwt does not verify signatures and always reports verified: false. JWE tokens are rejected and ES*/PS* tokens cannot be verified. Pin the package version so updates cannot change what runs.

Installation

In SourceWeft

  1. Open JWT Tools in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

jwt-tools MCP server

Decodes JSON Web Tokens without verifying them (and says so in the output), flags risky algorithms and claims, verifies HS256/384/512 and RS256/384/512 signatures when you supply the key, and mints tokens for test fixtures. Pure node:crypto; no network, no files.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
decode_jwttoken, now?, max_ttl_hours?Header, payload, ISO timestamps and findings: alg none or missing, empty signature, jku/x5u/jwk in the header, expired, not yet valid, missing exp/iat/aud/iss/sub/jti, lifetime above the threshold (default 24 h), millisecond timestamps, claims named like secrets. Always reports verified: false.
verify_jwttoken, key, algorithm, audience?, issuer?, now?, clock_tolerance_seconds?Signature check for exactly the given algorithm (a token whose header says anything else fails without a cryptographic check, which blocks algorithm confusion), then exp (required), nbf, aud, iss. Returns valid, signature_valid, claims_valid and reasons.
sign_test_jwtpayload, key, algorithm, expires_in_seconds?, now?Signs a claims object for tests. HS* takes a shared secret, RS* a PEM private key.

Install

Claude Code:

bash
claude mcp add jwt-tools -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "jwt-tools": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/jwt-tools/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: None. Keys are used for the one call and not stored.
  • Telemetry: none.

Notes

  • HMAC comparison uses crypto.timingSafeEqual.
  • RS* verification accepts a PEM public key, certificate or private key (the public part is derived).
  • JWE (encrypted, five-part) tokens are rejected; ES* and PS* tokens decode but cannot be verified here.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-jwt-toolsnpm test -w @basitalisandhu/mcp-jwt-tools

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

Source: packages/jwt-tools/README.md at commit 58c8c95

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 5, 2026