JWT Tools

io.github.basitalisandhuv0.1.1更新於 Oct 5, 2026

Decode JWTs without verifying, flag risky algorithms and claims, verify HS256 or RS256 with a key.

概覽

AI 產生的概覽

透過本機 stdio 伺服器解碼、檢查並驗證 JSON Web Token,也能產生測試用權杖。

功能
提供三個工具:decode_jwt 在不驗證簽章的情況下讀取權杖標頭與內容,回傳 ISO 時間戳與發現項目,例如 alg 為 none 或缺少、簽章為空、標頭含 jku/x5u/jwk、已過期或尚未生效、缺少標準宣告、有效期限過長、毫秒時間戳,以及名稱類似密鑰的宣告。verify_jwt 依指定演算法檢查 HS256/384/512 或 RS256/384/512 簽章,並驗證 exp、nbf、aud、iss。sign_test_jwt 可為測試簽署宣告物件。
適用情境
適合偵錯驗證流程、檢視權杖宣告與到期時間、判斷權杖是否以有風險的演算法簽署,或為測試產生一次性權杖。它是本機開發工具,而非正式環境的驗證服務。
執行需求
以 stdio 在本機執行,不需要網路、檔案或帳號。可用 npx 安裝並固定套件版本,或在取出原始碼後以 Node.js 執行 npm install 與 npm run build。另已發布 Docker 映像 ghcr.io/basitalisandhu/mcp-jwt-tools:0.1.1。金鑰透過工具參數逐次傳入。
安裝前請注意
verify_jwt 與 sign_test_jwt 需要傳入金鑰參數,因此真實密鑰或私鑰可能經過助理與模型內容;README 說明金鑰僅用於該次呼叫且不會被儲存。decode_jwt 不驗證簽章,一律回報 verified: false。JWE 權杖會被拒絕,ES*/PS* 權杖無法在此驗證。請固定套件版本,以免更新改變實際執行的內容。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 JWT Tools,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

jwt-tools MCP server

Decodes JSON Web Tokens without verifying them (and says so in the output), flags risky algorithms and claims, verifies HS256/384/512 and RS256/384/512 signatures when you supply the key, and mints tokens for test fixtures. Pure node:crypto; no network, no files.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
decode_jwttoken, now?, max_ttl_hours?Header, payload, ISO timestamps and findings: alg none or missing, empty signature, jku/x5u/jwk in the header, expired, not yet valid, missing exp/iat/aud/iss/sub/jti, lifetime above the threshold (default 24 h), millisecond timestamps, claims named like secrets. Always reports verified: false.
verify_jwttoken, key, algorithm, audience?, issuer?, now?, clock_tolerance_seconds?Signature check for exactly the given algorithm (a token whose header says anything else fails without a cryptographic check, which blocks algorithm confusion), then exp (required), nbf, aud, iss. Returns valid, signature_valid, claims_valid and reasons.
sign_test_jwtpayload, key, algorithm, expires_in_seconds?, now?Signs a claims object for tests. HS* takes a shared secret, RS* a PEM private key.

Install

Claude Code:

bash
claude mcp add jwt-tools -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "jwt-tools": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/jwt-tools/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: None. Keys are used for the one call and not stored.
  • Telemetry: none.

Notes

  • HMAC comparison uses crypto.timingSafeEqual.
  • RS* verification accepts a PEM public key, certificate or private key (the public part is derived).
  • JWE (encrypted, five-part) tokens are rejected; ES* and PS* tokens decode but cannot be verified here.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-jwt-toolsnpm test -w @basitalisandhu/mcp-jwt-tools

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

來源:packages/jwt-tools/README.md,提交 58c8c95

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 5, 2026