
JWT Tools
io.github.basitalisandhuv0.1.1更新於 Oct 5, 2026
Decode JWTs without verifying, flag risky algorithms and claims, verify HS256 or RS256 with a key.
概覽
透過本機 stdio 伺服器解碼、檢查並驗證 JSON Web Token,也能產生測試用權杖。
- 功能
- 提供三個工具:decode_jwt 在不驗證簽章的情況下讀取權杖標頭與內容,回傳 ISO 時間戳與發現項目,例如 alg 為 none 或缺少、簽章為空、標頭含 jku/x5u/jwk、已過期或尚未生效、缺少標準宣告、有效期限過長、毫秒時間戳,以及名稱類似密鑰的宣告。verify_jwt 依指定演算法檢查 HS256/384/512 或 RS256/384/512 簽章,並驗證 exp、nbf、aud、iss。sign_test_jwt 可為測試簽署宣告物件。
- 適用情境
- 適合偵錯驗證流程、檢視權杖宣告與到期時間、判斷權杖是否以有風險的演算法簽署,或為測試產生一次性權杖。它是本機開發工具,而非正式環境的驗證服務。
- 執行需求
- 以 stdio 在本機執行,不需要網路、檔案或帳號。可用 npx 安裝並固定套件版本,或在取出原始碼後以 Node.js 執行 npm install 與 npm run build。另已發布 Docker 映像 ghcr.io/basitalisandhu/mcp-jwt-tools:0.1.1。金鑰透過工具參數逐次傳入。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 JWT Tools,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
jwt-tools MCP server
Decodes JSON Web Tokens without verifying them (and says so in the output), flags risky algorithms and claims, verifies HS256/384/512 and RS256/384/512 signatures when you supply the key, and mints tokens for test fixtures. Pure node:crypto; no network, no files.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/jwt-tools/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network: None.
- Local files: None. Keys are used for the one call and not stored.
- Telemetry: none.
Notes
- HMAC comparison uses
crypto.timingSafeEqual. - RS* verification accepts a PEM public key, certificate or private key (the public part is derived).
- JWE (encrypted, five-part) tokens are rejected; ES* and PS* tokens decode but cannot be verified here.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
來源:packages/jwt-tools/README.md,提交 58c8c95
工具
0版本歷史
1- v0.1.1最新Oct 5, 2026


