Decode a JWT header + payload. Does NOT verify the signature — validation must happen at the token source.
This page documents the HTTP endpoint POST /api/tools/jwt-decode/execute. See the MCP reference →
Call it over REST
POST https://api.findutils.com/api/tools/jwt-decode/execute · no API keys · 60 requests/min per IP
Execute — verified arguments
curl -X POST https://api.findutils.com/api/tools/jwt-decode/execute \
-H "Content-Type: application/json" \
-d '{
"token": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ4In0.sig"
}' Parameter schema for this endpoint
curl https://api.findutils.com/api/tools/jwt-decode Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| token | string | yes | JWT token (3 dot-separated base64url segments). |
Example arguments (verified)
{
"token": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ4In0.sig"
} Also an MCP tool
Claude, Cursor, and any MCP client can call this tool as
findutils:jwt_decode after one connect command.
Connect once
claude mcp add findutils --transport http https://mcp.findutils.com/ More Security tools
Base32 Encode
Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
Data Sanitizer
Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
Dnpm Configurator
Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml, .dnpm/secc
Email Header Analyzer
Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop delays,
Hash Comparison Tool
Hash text with SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.
Jwt Generator
Generate a signed JWT (HS256, HS384, or HS512 via HMAC) and return the token plus the decoded header and payload.
Jwt Security Validator
Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signatu
Password Breach Checker
Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API.