Api Jwt Decode
api_jwt_decodeDecode a JWT header and payload WITHOUT signature verification. ?token= [HTTP x402 price: $0.001]
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| params | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
api_jwt_decodeDecode a JWT header and payload WITHOUT signature verification. ?token= [HTTP x402 price: $0.001]
| Name | Required | Description | Default |
|---|---|---|---|
| params | No |
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Changes observed during successful MCP inspections. Dates show when Glama detected each change.
Input schema / properties / params / additionalPropertiesRemoved value: -trueInput schema / properties / params / propertiesAdded value: +{
+ "token": {
+ "anyOf": [
+ {
+ "type": "string"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "default": null
+ }
+}Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the burden, and it does disclose a key behavioral trait: no signature verification is performed. It also adds the invocation style and price. It does not cover error behavior for malformed JWTs, but the most important behavioral boundary is clearly stated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is one compact sentence plus a usage hint and price. The core behavior is front-loaded, and every element earns its place without redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple single-parameter utility, the description covers the core operation, the no-verification caveat, the query syntax, and the cost. An output schema exists, so return-value details need not be spelled out. It could mention invalid-token behavior, but the overall context is sufficient for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema provides only a generic 'token' string with no description, and coverage is 0%, so the description must compensate. It adds meaning by showing the exact query format '?token=<jwt>' and clarifying that the token is a JWT. For a single-parameter tool, this is sufficient added semantic value.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb-resource pair: 'Decode a JWT header and payload.' It also explicitly states what the tool does NOT do ('WITHOUT signature verification'), which distinguishes it from any verification-oriented JWT operation and from the sibling utility tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The usage is implied by the description: use this when you need to decode a JWT without verifying its signature. However, there is no explicit guidance about when not to use it or which alternative tool to choose, though the sibling list is broad enough that confusion is unlikely.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.
Several tools have unclear boundaries: api_search and api_serp_google both return Google results, api_scrape and api_render_text both extract page text, and api_hash_multi overlaps with api_sha256 for SHA-256/SHA-512. While many tools are distinct, these overlapping pairs create real misselection risk.
Every tool follows the same api_<snake_case> pattern with no mixed conventions or casing styles. The prefix makes the server immediately recognizable and the action/resource is consistently readable across all 44 tools.
44 tools is well over the 25+ threshold for a well-scoped set, making the server feel like a grab-bag of unrelated utilities. Even though each tool is small and individually useful, the overall surface is too large and would benefit from consolidation into focused sub-servers.
The set covers many common utility categories—encodings, conversions, text analysis, web scraping, SEO, and trends—but has notable one-way gaps: CSV/YAML/TOML all convert to JSON but not back, and markdown converts to HTML but not the reverse. The broad domain makes full completeness hard to define, so only major reverse-conversion gaps stand out.