
JWT Tools
io.github.basitalisandhuv0.1.1Updated Oct 5, 2026
Decode JWTs without verifying, flag risky algorithms and claims, verify HS256 or RS256 with a key.
Overview
Decode, inspect and verify JSON Web Tokens, and mint test tokens, using a local stdio server.
- What it does
- Provides three tools: decode_jwt reads a token's header and payload without verifying it, returning ISO timestamps and findings such as alg none or missing, empty signature, jku/x5u/jwk headers, expired or not-yet-valid times, missing standard claims, long lifetimes, millisecond timestamps and secret-like claim names. verify_jwt checks an HS256/384/512 or RS256/384/512 signature against a supplied key for exactly the given algorithm, then validates exp, nbf, aud and iss. sign_test_jwt signs a claims object for test fixtures.
- When to use it
- Useful when debugging authentication flows, inspecting a token's claims and expiry, checking whether a token is signed with a risky algorithm, or generating throwaway tokens for tests. It is a local developer utility rather than a production verification service.
- Requirements
- Runs locally over stdio; no network, files or accounts. Install via npx with the pinned package version, or from a checkout with Node.js after npm install and npm run build. Docker image ghcr.io/basitalisandhu/mcp-jwt-tools:0.1.1 is also published. Keys are supplied per call as tool arguments.
Installation
In SourceWeft
- Open JWT Tools in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
jwt-tools MCP server
Decodes JSON Web Tokens without verifying them (and says so in the output), flags risky algorithms and claims, verifies HS256/384/512 and RS256/384/512 signatures when you supply the key, and mints tokens for test fixtures. Pure node:crypto; no network, no files.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/jwt-tools/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network: None.
- Local files: None. Keys are used for the one call and not stored.
- Telemetry: none.
Notes
- HMAC comparison uses
crypto.timingSafeEqual. - RS* verification accepts a PEM public key, certificate or private key (the public part is derived).
- JWE (encrypted, five-part) tokens are rejected; ES* and PS* tokens decode but cannot be verified here.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
Source: packages/jwt-tools/README.md at commit 58c8c95
Tools
0Version history
1- v0.1.1LatestOct 5, 2026


