Skip to main content
Glama

jwt_decode

Decode a JWT and extract its claims (subject, issuer, audience, expiration with expired flag, issued-at, not-before, algorithm, key id). Decode-only — signature NOT verified. -> /x/util/jwt-decode. Pay-per-call ($0.002 USDC).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
tokenYesThe JWT string to decode

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does disclose the safety-critical trait: signatures are NOT verified. It also states the pricing model (pay-per-call, $0.002 USDC), which matters for agent decision-making. It omits error behavior for malformed tokens and any rate/limit context, keeping it short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core action and the decode-only caveat, then tacks on the route and price. Every element is short, though the parenthetical claim list and the '-> /x/util/jwt-decode' internal route make it slightly denser than necessary for an agent.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, and the description compensates by enumerating the returned claim fields, so an agent knows what to expect. Cost and the verification caveat round it out. Minor gaps remain around malformed-input behavior, but nothing essential to invoking it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% with a single 'token' parameter already documented as 'The JWT string to decode', so the schema does the heavy lifting. The description adds no syntax, size, or format constraints beyond that. Baseline 3 is appropriate for a fully-documented single parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (decode) and resource (JWT), then enumerates exactly what is extracted (subject, issuer, audience, expiration with expired flag, issued-at, not-before, algorithm, key id). No sibling tool overlaps with JWT decoding, so the boundary is unambiguous from the definition alone.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear conditional context via 'Decode-only — signature NOT verified', which tells an agent when this tool is inappropriate (any use requiring trust in the token's authenticity). It does not name an alternative verification tool, but no such sibling exists in the list, so the guidance is effectively complete for this catalog.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources