Generate a signed JWT (HS256, HS384, or HS512 via HMAC) and return the token plus the decoded header and payload. The payload contains sub, name, iat, exp, and any custom claims. Asymmetric algorithms (RS*/ES*) are not supported.
This page documents the MCP tool findutils:jwt_generator. See the REST reference →
Call it over MCP
Tool name findutils:jwt_generator
· no API keys · 120 requests/min per IP
Claude Code
claude mcp add findutils --transport http https://mcp.findutils.com/ Claude Desktop — claude_desktop_config.json
{
"mcpServers": {
"findutils": {
"url": "https://mcp.findutils.com/"
}
}
} Raw JSON-RPC (any MCP client) — verified example
curl -X POST https://mcp.findutils.com/ \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "jwt_generator",
"arguments": {
"secret": "my-secret",
"subject": "u1",
"name": "Ann",
"expires_in": 3600
}
}
}' Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| secret | string | yes | The HMAC secret used to sign the token. |
| algorithm | string (HS256 | HS384 | HS512) | no | Signing algorithm. Default: HS256. Default: "HS256". |
| subject | string | no | The "sub" claim. Default: "1234567890". Default: "1234567890". |
| name | string | no | The "name" claim. Default: "John Doe". Default: "John Doe". |
| expires_in | integer | no | Seconds until expiry; exp = iat + expires_in. Default: 3600. Default: 3600. |
| custom_claims | object | no | Extra claims merged into the payload. An object, or a JSON object string. |
| issued_at | integer | no | Unix timestamp (seconds) for the "iat" claim. Default: now. |
Example arguments (verified)
{
"secret": "my-secret",
"subject": "u1",
"name": "Ann",
"expires_in": 3600
} Also a REST endpoint
The same tool answers plain HTTP at
POST /api/tools/jwt-generator/execute — no key, 60 requests/min.
More Security tools
Base32 Encode
Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
Data Sanitizer
Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
Dnpm Configurator
Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml, .dnpm/secc
Email Header Analyzer
Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop delays,
Hash Comparison Tool
Hash text with SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.
Jwt Decode
Decode a JWT header + payload.
Jwt Security Validator
Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signatu
Password Breach Checker
Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API.