Jwt Security Validator

Security REST API MCP

Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signature presence) plus an overall valid flag. Does NOT verify the signature — it only inspects claims and header fields.

This page documents the MCP tool findutils:jwt_security_validator. See the REST reference →

Call it over MCP

Tool name findutils:jwt_security_validator · no API keys · 120 requests/min per IP

Claude Code

claude mcp add findutils --transport http https://mcp.findutils.com/

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "findutils": {
      "url": "https://mcp.findutils.com/"
    }
  }
}

Raw JSON-RPC (any MCP client) — verified example

curl -X POST https://mcp.findutils.com/ \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "jwt_security_validator",
      "arguments": {
        "token": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ4In0.sig"
      }
    }
  }'

Input schema

Argument Type Required Description
token string yes The JWT to inspect (three dot-separated base64url segments).
now integer no Unix timestamp (seconds) to evaluate time claims against. Default: current time.

Example arguments (verified)

{
  "token": "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ4In0.sig"
}

Also a REST endpoint

The same tool answers plain HTTP at POST /api/tools/jwt-security-validator/execute — no key, 60 requests/min.

Open the REST reference for Jwt Security Validator →

More Security tools