JWT Auditor
This MCP server provides AI assistants with advanced JWT security auditing capabilities through four specialized tools for decoding, vulnerability analysis, secret brute-forcing, and token generation/editing. Built using Python with FastMCP and the cryptography library, it offers JWT header and payload decoding without verification, comprehensive vulnerability detection including algorithm confusion attacks, missing security claims, sensitive data exposure, and header injection risks, HMAC secret brute-forcing for HS256/HS384/HS512 tokens using customizable wordlists, and JWT generation with support for both symmetric (HS*) and asymmetric (RS*) algorithms. Inspired by the JWTAuditor tool, the implementation performs all operations locally without sending tokens to external services, includes built-in security checks for token lifetime analysis and replay attack detection, and supports common JWT security testing workflows, making it valuable for penetration testing, security assessments, and building AI assistants that need programmatic access to JWT analysis without manual security tool navigation.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-02.
Scan details: Circle-IR · 2026-09-02 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- finance
- Source
- PulseMCP
- Repository
- github.com/mohdhaji87/jwtauditormcp
- Author type
- human
- Last scanned
- 2026-09-02
- Updated
- 2026-09-02
Use via MCP
Resolve JWT Auditor from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.