Jwt Security Validator

Security REST API MCP

Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signature presence) plus an overall valid flag. Does NOT verify the signature — it only inspects claims and header fields.

This page documents the HTTP endpoint POST /api/tools/jwt-security-validator/execute. See the MCP reference →

Call it over REST

POST https://api.findutils.com/api/tools/jwt-security-validator/execute · no API keys · 60 requests/min per IP

Execute — verified arguments

curl -X POST https://api.findutils.com/api/tools/jwt-security-validator/execute \
  -H "Content-Type: application/json" \
  -d '{
    "token": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ4In0.sig"
  }'

Parameter schema for this endpoint

curl https://api.findutils.com/api/tools/jwt-security-validator

Interactive docs · OpenAPI 3.1 spec · All REST tools

Input schema

Argument Type Required Description
token string yes The JWT to inspect (three dot-separated base64url segments).
now integer no Unix timestamp (seconds) to evaluate time claims against. Default: current time.

Example arguments (verified)

{
  "token": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ4In0.sig"
}

Also an MCP tool

Claude, Cursor, and any MCP client can call this tool as findutils:jwt_security_validator after one connect command.

Connect once

claude mcp add findutils --transport http https://mcp.findutils.com/
Open the MCP reference for Jwt Security Validator →

More Security tools