Skip to main content
Glama

Decode a JWT (no verification)

jwt_decode
Read-onlyIdempotent

Decode a JSON Web Token into its header and payload so you can inspect claims (iss, exp, sub, scopes). The signature is NOT verified and no secret is required or stored. Use to read a token during debugging.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
tokenYesThe JWT (three dot-separated segments).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
headerNoThe decoded JWT header object.
exp_isoNoExpiry as ISO 8601, if present.
expiredNoWhether the token is past its exp, if present.
payloadNoThe decoded JWT payload (claims).

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint and idempotentHint, but the description adds critical behavioral context: 'The signature is NOT verified and no secret is required or stored.' This goes beyond the structured annotations by clarifying security implications and output content (header and payload).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences with zero filler. The first sentence states purpose and output, the second highlights the critical caveat, and the third gives a direct use case. Information is front-loaded and every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple single-parameter tool with an output schema declared, the description fully covers the purpose, behavior, output, and use case. It also addresses security-relevant aspects (no verification, no secret storage), making it complete for both selection and invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% coverage with a description for the token parameter ('The JWT (three dot-separated segments)'). The tool description adds some context about what the decoded result contains, but it doesn't elaborate on the parameter beyond what the schema already states, so it meets the baseline without exceeding it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's action: 'Decode a JSON Web Token into its header and payload' and the purpose 'so you can inspect claims.' It distinguishes itself from sibling tools by specifically targeting JWT decoding, with the title also adding 'no verification.'

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit usage context: 'Use to read a token during debugging.' It also implies a when-not by stating 'The signature is NOT verified,' signaling this is not for validation. However, it doesn't name alternative tools for verification, so it falls short of full exclusion guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.3/5.0
Disambiguation5/5

Each tool has a clearly distinct purpose: base64 encoding, color conversion, string counting, hashing, image format comparison, JSON formatting, JWT decoding, image optimization, QR code generation, slugification, storage capacity calculation, and UUID generation. No two tools overlap in functionality.

Naming Consistency4/5

Tool names are mostly consistent using lowercase and underscores, but they mix patterns: some are nouns (color, hash, uuid), some verbs (count, slugify), and some verb_noun pairs (jwt_decode, optimize_image). This minor inconsistency is still readable.

Tool Count5/5

With 12 tools, the count is well within the ideal range. Each tool serves a specific and useful utility function, making the set well-scoped for a general-purpose developer toolkit.

Completeness4/5

The tool set covers a broad range of common web development utilities (encoding, colors, hashing, JSON, images, UUIDs). Minor gaps like URL encoding or HTML escaping are missing, but the core functionalities are well-represented.