Skip to main content
Glama
mohdhaji87

JWT Auditor MCP Server

by mohdhaji87

Related Servers

Alternatives to JWT Auditor MCP Server

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables AI agents to audit JSON Web Tokens (JWTs) and other token formats for security vulnerabilities, including HMAC secret cracking, live JWKS verification, and CVE fingerprinting.
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      MCP server that provides AI clients with 26 security and developer tools, enabling tasks like JWT decoding, HTTP header analysis, and phishing URL inspection.
      -
    • A
      license
      A
      quality
      D
      maintenance
      Enables cryptographic operations including hashing, encoding/decoding, ID generation, password tools, and JWT inspection via MCP.
      5
      36 npm
      MIT
    • F
      license
      Not graded
      quality
      B
      maintenance
      An MCP server that extends kali-mcp with cloud (AWS/Azure/GCP), API/GraphQL/JWT, OSINT, container/K8s, IaC/SAST, mobile, binary analysis, and reporting tools, all accessible via an HTTP MCP endpoint.
      -
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables security analysis through MCP-compatible clients, including URL phishing checks, email header verification, JWT decoding, password strength analysis, and leaked secret scanning in code.
      186 npm
      MIT

    TDQS

    A3.6/5.0

    Scored across 4 tools

    Disambiguation5/5

    Each tool has a clearly distinct purpose: jwt_analyze for vulnerability assessment, jwt_bruteforce for secret cracking, jwt_decode for raw decoding, and jwt_generate for token creation. There is no overlap in functionality, making it easy for an agent to select the correct tool for a specific task.

    Naming Consistency5/5

    All tool names follow a consistent 'jwt_' prefix with a descriptive action suffix (analyze, bruteforce, decode, generate), using snake_case uniformly. This predictable pattern enhances readability and reduces confusion for agents.

    Tool Count5/5

    With 4 tools, the server is well-scoped for JWT auditing, covering essential operations like analysis, decoding, generation, and brute-forcing. Each tool earns its place without being too sparse or overwhelming, fitting typical use cases in this domain.

    Completeness4/5

    The toolset provides strong coverage for core JWT auditing tasks, including decode, generate, analyze, and brute-force. A minor gap exists in lacking a tool for verifying JWTs with known keys, which could be useful but is not critical for the stated purpose, as agents can work around this.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues