home / skills / aidotnet / moyucode / jwt-decoder
This skill enables decoding, verifying, and generating JWTs across algorithms, helping you secure tokens and streamline authentication workflows.
npx playbooks add skill aidotnet/moyucode --skill jwt-decoderReview the files below or copy the command above to add this skill to your agents.
---
name: jwt-decoder
description: 解码、验证和生成JWT令牌,支持多种算法。
metadata:
short-description: JWT令牌工具
source:
repository: https://github.com/jpadilla/pyjwt
license: MIT
---
# JWT Decoder Tool
## Description
Decode, verify, and generate JWT (JSON Web Tokens) with support for HS256, RS256, and other algorithms.
## Trigger
- `/jwt` command
- User needs to decode JWT
- User wants to verify tokens
## Usage
```bash
# Decode JWT (no verification)
python scripts/jwt_decoder.py decode "eyJhbGciOiJIUzI1NiIs..."
# Verify JWT with secret
python scripts/jwt_decoder.py verify "eyJ..." --secret "your-secret"
# Generate JWT
python scripts/jwt_decoder.py generate --payload '{"sub": "user123"}' --secret "secret"
```
## Tags
`jwt`, `token`, `auth`, `decode`, `security`
## Compatibility
- Codex: ✅
- Claude Code: ✅
This skill decodes, verifies, and generates JWT (JSON Web Tokens) with support for common algorithms like HS256 and RS256. It provides quick token inspection, signature verification against secrets or keys, and token creation from JSON payloads. Designed for developers and security engineers needing a lightweight token tool.
The skill accepts raw JWT strings and splits header, payload, and signature for readable decoding without altering the token. For verification, it checks the signature using the provided secret or public key and validates standard claims (exp, nbf, iat) when present. It can also generate new tokens from a JSON payload and sign them with a chosen algorithm and key.
Can it verify tokens signed with RS256?
Yes. Provide the appropriate public key for verification; private keys are used only for signing when generating tokens.
Does decoding validate the token automatically?
No. Decoding only shows header and payload. Perform verification with a secret or key to confirm authenticity and claim validity.