Introduction¶
In the DSH plugin ecosystem, when developing or debugging intelligent agents, it is often necessary to quickly inspect the internal structure of a JWT token or verify its expiration status. A common approach is to use external command-line tools or write temporary parsing scripts. The dsh-jwt plugin provides this capability directly within the DSH environment.
Plugin Description¶
dsh-jwt is a plugin maintained by uckkk and belongs to the admin-security category. It is a pure Node.js tool whose main function is to decode the header and payload of a JWT and determine whether the token has expired, but it does not perform signature verification.
Installation and Enablement¶
The installation command is as follows:
dsh plugin add dsh-jwt
After successful installation, the plugin is added to the dsh.profile.bundles field in the profile’s package.json.
Core Features¶
The plugin provides the following capabilities:
* Decode the header/payload of a JWT
* Determine whether it has expired (without signature verification)
* Provide the tool: jwt_decode
Typical Usage¶
In a session, you can invoke the jwt_decode tool to view the token’s content and status.
Example usage:
jwt_decode(token="eyJhbGci...")
This returns the decoded token content, helping you assess its validity and the data it contains.
Use Cases and Notes¶
This plugin is suitable for the development and debugging stages, used to quickly verify token structure. Note that the plugin runs with the permissions of the current DSH process and consists of third-party code. Before installing, it is recommended to review the source code yourself to ensure it meets your security requirements. It is open-sourced under the MIT license.