When developing agents in a DSH environment, debugging external API requests often involves JWT tokens. Developers need to quickly inspect token headers, payloads, and claims such as expiration time, without writing extra decoding scripts or manually handling Base64. The dsh-jwt plugin provides decoding and inspection capabilities directly within the DSH environment.
What This Is¶
This is a DSH plugin maintained by ZhijiangTang, categorized under networking tools and released under the MIT license. It focuses on splitting a JWT token into three parts and decoding them, while parsing time-related claims for debugging and inspection.
Core Features¶
- JWT Decoding: Splits
header.payload.signatureand performs Base64url decoding on the header and payload. - Time Claim Interpretation: Parses
exp(expiration),iat(issued at), andnbf(not before) times, with support for UTC and local time display. - Status Checking: Checks whether the token is expired, the remaining valid time, etc.
Installation and Enabling¶
Use the following command to add the plugin to the specified profile:
dsh plugin --profile <你的 profile> add file:./plugins/dsh-jwt
After installation, you usually need to restart the profile to load the plugin.
Usage¶
It registers the jwt_decode tool, with the parameter token (string type, required). Enter a complete JWT token string to execute decoding.
Output Fields¶
| Field | Type | Description |
|---|---|---|
ok |
boolean | Whether parsing succeeded (both header and payload are valid JSON) |
parts |
integer | Number of segments obtained by splitting on . (2 or 3) |
header |
object / null | Decoded JOSE header |
payload |
object / null | Decoded payload (claims) |
signaturePresent |
boolean | Whether a signature segment is present (existence check only, no validation) |
issuedAt |
object? | iat claim: includes value, UTC time, local time |
notBefore |
object? | nbf claim: includes value, UTC time, local time, whether it is in effect |
expiresAt |
object? | exp claim: includes value, UTC time, local time, whether expired, remaining seconds |
expired |
boolean? | Whether it is expired (based on exp) |
remainingSeconds |
number? | Remaining seconds until expiration (negative if already expired) |
errors |
string[] | Error messages from decoding or parsing (no exception is thrown when parsing fails) |
Use Cases and Notes¶
- Debugging use: Suitable for quickly inspecting token structure, time claims, and payload content during development and debugging.
- Security warning: No signature verification. The plugin does not validate signature validity, key matching, or claims such as
iss/aud. Do not make any security decisions, such as authentication, authorization, or trusting a source, based on this tool’s output. Use a library capable of key validation when trusted verification is required. - Fault tolerance: If the token is malformed or JSON parsing fails, the tool returns
ok: falseand anerrorslist instead of throwing an exception that interrupts the flow.
Summary¶
dsh-jwt provides DSH developers with a lightweight JWT debugging tool focused on structural parsing and time checking. For more information or to view the source code, visit GitHub.