JWT Tools

io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026

Decode JWTs without verifying, flag risky algorithms and claims, verify HS256 or RS256 with a key.

概览

AI 生成的概览

通过本地 stdio 服务器解码、检查并验证 JSON Web Token,也可生成测试用令牌。

功能
提供三个工具:decode_jwt 在不验证签名的情况下读取令牌头部与载荷,返回 ISO 时间戳以及发现项,例如 alg 为 none 或缺失、签名为空、头部含 jku/x5u/jwk、已过期或尚未生效、缺少标准声明、有效期过长、毫秒级时间戳以及名称类似密钥的声明。verify_jwt 按指定算法校验 HS256/384/512 或 RS256/384/512 签名,并检查 exp、nbf、aud、iss。sign_test_jwt 可为测试签发声明对象。
适用场景
适合调试认证流程、查看令牌声明与过期时间、判断令牌是否使用有风险的算法签名,或为测试生成一次性令牌。它是本地开发工具,而非生产环境的验证服务。
运行要求
以 stdio 在本地运行,不需要网络、文件或账号。可用 npx 安装并固定包版本,或在检出代码后用 Node.js 执行 npm install 与 npm run build。也发布了 Docker 镜像 ghcr.io/basitalisandhu/mcp-jwt-tools:0.1.1。密钥通过工具参数按次传入。
安装前请注意
verify_jwt 与 sign_test_jwt 需要传入密钥参数,因此真实密钥或私钥可能经过助手与模型上下文;README 说明密钥仅用于当次调用且不会被存储。decode_jwt 不验证签名,始终返回 verified: false。JWE 令牌会被拒绝,ES*/PS* 令牌无法在此验证。请固定包版本,以免更新改变实际运行内容。

安装

在 SourceWeft 中

  1. 打开 控制台中的 JWT Tools,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

jwt-tools MCP server

Decodes JSON Web Tokens without verifying them (and says so in the output), flags risky algorithms and claims, verifies HS256/384/512 and RS256/384/512 signatures when you supply the key, and mints tokens for test fixtures. Pure node:crypto; no network, no files.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
decode_jwttoken, now?, max_ttl_hours?Header, payload, ISO timestamps and findings: alg none or missing, empty signature, jku/x5u/jwk in the header, expired, not yet valid, missing exp/iat/aud/iss/sub/jti, lifetime above the threshold (default 24 h), millisecond timestamps, claims named like secrets. Always reports verified: false.
verify_jwttoken, key, algorithm, audience?, issuer?, now?, clock_tolerance_seconds?Signature check for exactly the given algorithm (a token whose header says anything else fails without a cryptographic check, which blocks algorithm confusion), then exp (required), nbf, aud, iss. Returns valid, signature_valid, claims_valid and reasons.
sign_test_jwtpayload, key, algorithm, expires_in_seconds?, now?Signs a claims object for tests. HS* takes a shared secret, RS* a PEM private key.

Install

Claude Code:

bash
claude mcp add jwt-tools -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "jwt-tools": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/jwt-tools/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: None. Keys are used for the one call and not stored.
  • Telemetry: none.

Notes

  • HMAC comparison uses crypto.timingSafeEqual.
  • RS* verification accepts a PEM public key, certificate or private key (the public part is derived).
  • JWE (encrypted, five-part) tokens are rejected; ES* and PS* tokens decode but cannot be verified here.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-jwt-toolsnpm test -w @basitalisandhu/mcp-jwt-tools

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

来源:packages/jwt-tools/README.md,提交 58c8c95

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.1最新Oct 5, 2026