
JWT Tools
io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026
Decode JWTs without verifying, flag risky algorithms and claims, verify HS256 or RS256 with a key.
概览
通过本地 stdio 服务器解码、检查并验证 JSON Web Token,也可生成测试用令牌。
- 功能
- 提供三个工具:decode_jwt 在不验证签名的情况下读取令牌头部与载荷,返回 ISO 时间戳以及发现项,例如 alg 为 none 或缺失、签名为空、头部含 jku/x5u/jwk、已过期或尚未生效、缺少标准声明、有效期过长、毫秒级时间戳以及名称类似密钥的声明。verify_jwt 按指定算法校验 HS256/384/512 或 RS256/384/512 签名,并检查 exp、nbf、aud、iss。sign_test_jwt 可为测试签发声明对象。
- 适用场景
- 适合调试认证流程、查看令牌声明与过期时间、判断令牌是否使用有风险的算法签名,或为测试生成一次性令牌。它是本地开发工具,而非生产环境的验证服务。
- 运行要求
- 以 stdio 在本地运行,不需要网络、文件或账号。可用 npx 安装并固定包版本,或在检出代码后用 Node.js 执行 npm install 与 npm run build。也发布了 Docker 镜像 ghcr.io/basitalisandhu/mcp-jwt-tools:0.1.1。密钥通过工具参数按次传入。
安装
在 SourceWeft 中
- 打开 控制台中的 JWT Tools,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
jwt-tools MCP server
Decodes JSON Web Tokens without verifying them (and says so in the output), flags risky algorithms and claims, verifies HS256/384/512 and RS256/384/512 signatures when you supply the key, and mints tokens for test fixtures. Pure node:crypto; no network, no files.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/jwt-tools/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network: None.
- Local files: None. Keys are used for the one call and not stored.
- Telemetry: none.
Notes
- HMAC comparison uses
crypto.timingSafeEqual. - RS* verification accepts a PEM public key, certificate or private key (the public part is derived).
- JWE (encrypted, five-part) tokens are rejected; ES* and PS* tokens decode but cannot be verified here.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
来源:packages/jwt-tools/README.md,提交 58c8c95
工具
0版本历史
1- v0.1.1最新Oct 5, 2026


