# JWT Auditor

> Use this tool when you need to audit JSON Web Tokens (JWTs) for security vulnerabilities, decode and analyze token headers and payloads, or generate and edit tokens with advanced security features. It solves problems related to token security, such as algorithm confusion attacks, sensitive data exposure, and header injection risks, and provides inputs for token decoding, vulnerability analysis, and secret brute-forcing, with outputs including token analysis reports and generated tokens. Ideal for use in penetration testing, security assessments, and building AI assistants that require programmatic JWT analysis.

Canonical page: https://skillsregistry.net/skills/mohdhaji87-jwt-auditor  
JSON: https://api.skillsregistry.net/v1/skills/mohdhaji87-jwt-auditor

## Description

This MCP server provides AI assistants with advanced JWT security auditing capabilities through four specialized tools for decoding, vulnerability analysis, secret brute-forcing, and token generation/editing. Built using Python with FastMCP and the cryptography library, it offers JWT header and payload decoding without verification, comprehensive vulnerability detection including algorithm confusion attacks, missing security claims, sensitive data exposure, and header injection risks, HMAC secret brute-forcing for HS256/HS384/HS512 tokens using customizable wordlists, and JWT generation with support for both symmetric (HS*) and asymmetric (RS*) algorithms. Inspired by the JWTAuditor tool, the implementation performs all operations locally without sending tokens to external services, includes built-in security checks for token lifetime analysis and replay attack detection, and supports common JWT security testing workflows, making it valuable for penetration testing, security assessments, and building AI assistants that need programmatic access to JWT analysis without manual security tool navigation.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** scanned
- **Last scanned:** 2026-09-02

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** finance
- **Updated:** 2026-09-02

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/mohdhaji87-jwt-auditor)
- **Repository:** <https://github.com/mohdhaji87/jwtauditormcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "mohdhaji87-jwt-auditor"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/mohdhaji87-jwt-auditor` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/mohdhaji87-jwt-auditor/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
