When developing agents in a DSH environment, debugging external API requests often involves JWT tokens. Developers need to quickly inspect token headers, payloads, and claims such as expiration time, without writing extra decoding scripts or manually handling Base64. The dsh-jwt plugin provides decoding and inspection capabilities directly within the DSH environment.

What This Is

This is a DSH plugin maintained by ZhijiangTang, categorized under networking tools and released under the MIT license. It focuses on splitting a JWT token into three parts and decoding them, while parsing time-related claims for debugging and inspection.

Core Features

  1. JWT Decoding: Splits header.payload.signature and performs Base64url decoding on the header and payload.
  2. Time Claim Interpretation: Parses exp (expiration), iat (issued at), and nbf (not before) times, with support for UTC and local time display.
  3. Status Checking: Checks whether the token is expired, the remaining valid time, etc.

Installation and Enabling

Use the following command to add the plugin to the specified profile:

dsh plugin --profile <你的 profile> add file:./plugins/dsh-jwt

After installation, you usually need to restart the profile to load the plugin.

Usage

It registers the jwt_decode tool, with the parameter token (string type, required). Enter a complete JWT token string to execute decoding.

Output Fields

Field Type Description
ok boolean Whether parsing succeeded (both header and payload are valid JSON)
parts integer Number of segments obtained by splitting on . (2 or 3)
header object / null Decoded JOSE header
payload object / null Decoded payload (claims)
signaturePresent boolean Whether a signature segment is present (existence check only, no validation)
issuedAt object? iat claim: includes value, UTC time, local time
notBefore object? nbf claim: includes value, UTC time, local time, whether it is in effect
expiresAt object? exp claim: includes value, UTC time, local time, whether expired, remaining seconds
expired boolean? Whether it is expired (based on exp)
remainingSeconds number? Remaining seconds until expiration (negative if already expired)
errors string[] Error messages from decoding or parsing (no exception is thrown when parsing fails)

Use Cases and Notes

  • Debugging use: Suitable for quickly inspecting token structure, time claims, and payload content during development and debugging.
  • Security warning: No signature verification. The plugin does not validate signature validity, key matching, or claims such as iss/aud. Do not make any security decisions, such as authentication, authorization, or trusting a source, based on this tool’s output. Use a library capable of key validation when trusted verification is required.
  • Fault tolerance: If the token is malformed or JSON parsing fails, the tool returns ok: false and an errors list instead of throwing an exception that interrupts the flow.

Summary

dsh-jwt provides DSH developers with a lightweight JWT debugging tool focused on structural parsing and time checking. For more information or to view the source code, visit GitHub.