JWT Payload Extractor

JWT Payload Extractor MCP Connector for Claude

A+

Extract and decode JWT payloads deterministically without cryptographic verification.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

The jwt-payload-extractor implements a deterministic decoding pipeline for inspecting JSON Web Token (JWT) payloads without cryptographic verification. The process begins by splitting the input string via the period delimiter to isolate the second segment. It then performs Base64URL normalization, specifically replacing hyphens (-) with plus signs (+) and underscores (_) with forward slashes (/), before applying standard Base64 decoding via atob. This allows for the extraction of claims such as 'sub', 'iat', or custom identifiers. The server also facilitates temporal analysis by parsing the 'exp' claim and comparing its Unix timestamp against the current system clock to determine token validity.

Available Tools

decode_jwt_payload, check_token_expiry, extract_token_identity

jwtauthdecodingpayloadtoken

3 tools expose this connector's capabilities to your AI agent.

extract_token_identity

Extracts a specific identity claim from a JWT token

check_token_expiry

Checks the expiration of a JWT token

decode_jwt_payload

Decodes the payload of a JWT string

See how to talk to your AI agent using JWT Payload Extractor.

Decode this JWT and tell me what the payload contains: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

{ "sub": "1234567890", "name": "John Doe", "iat": 1516239022 }

Is this token expired? eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE1MTYyMzkwMjJ9.signature

The expiration timestamp is 1516239022. Based on the current time, the token is expired.

Extract the 'user_role' from this token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX3JvbGUiOiJhZG1pbiJ9.signature

The value for the 'user_role' key is 'admin'.

No, the server focuses exclusively on the deterministic parsing of the payload segment. It does not utilize any cryptographic primitives or secret keys to validate the integrity of the signature segment. Tools available: `decode_jwt_payload`, `check_token_expiry`, `extract_token_identity`.

Related Connectors