Java decompiler MCP server. Explore, search, and decompile JAR, WAR, EAR, and AAR bytecode.
dejared MCP Server (io.github.hqkh4nh/dejared)
This Model Context Protocol (MCP) server provides tools to explore, search, and decompile Java bytecode. It targets common Java archive formats including JAR, WAR, EAR, and AAR. The server is packaged for Node.js and is distributed as an npm module named dejared-mcp.
π οΈ Key Features
Decompile Java bytecode from archive files
Explore and search within bytecode contents
Supports JAR, WAR, EAR, and AAR inputs
π Use Cases
Inspect compiled Java artifacts in JAR/WAR/EAR/AAR
Reverse-engineer or review class-file behavior via decompiled output
Analyze bytecode using tooling integrated through MCP
β‘ Developer Benefits
MCP integration for bytecode exploration and decompilation
Node.js 20+ distribution via npm (dejared-mcp)
Java 17+ oriented, per published badges
β οΈ Limitations
Only described as supporting Java decompilation of JAR/WAR/EAR/AAR bytecode
No additional tool count, configuration details, or supported decompiler engines are stated in the provided data
dejared-mcp is a Java decompiler and JAR analyzer that speaks the Model Context
Protocol. It lets an AI coding agent (Claude Code, Codex, Cursor, VS Code)
open a .jar, .war, .ear, or .aar, list what is inside, search its
bytecode, and decompile any class back to Java source using CFR, Vineflower,
or Procyon.
dejared-mcp is a Java-based MCP server distributed as an npm package.
It provides nine tools organized into three categories: discovery, hunting,
and deep analysis. AI assistants use these tools to navigate JAR file
structures, search for classes and string literals in bytecode, and
decompile .class files back to readable Java source code.
Reach for it whenever a dependency ships without sources: reading what a
third-party library actually does, recovering an application.yml or
MANIFEST.MF embedded in a JAR, following a stack trace into a library you
have no source for, or inspecting an obfuscated plugin or mod. It replaces
hand-running jar tf, unzip, javap, or a desktop decompiler.
Any ZIP-based Java archive works: .jar, .war, .ear, .aar, and
Spring Boot fat-jars.
The npm package acts as a thin wrapper that downloads and caches the
server JAR on first run, then spawns it via java -jar using stdio
transport.
Prerequisites
Node.js 20 or later
Java 17 or later (JRE is sufficient)
Quick Start
The best install is the plugin. One command pair gives your agent both halves:
the nine MCP tools, and the jar-analysis skill that tells it when to
reach for them instead of shelling out to jar tf, unzip, or javap.
bash
claude plugin marketplace add hqkh4nh/dejared-mcp
claude plugin install dejared@dejared-mcp-marketplace
The MCP server on its own gives an agent nine tools. It does not tell the agent
when to use them, so most agents keep reaching for jar tf, unzip -p, and
javap -p out of habit and never touch the tools you installed.
Routes JAR questions to those tools, picks the cheap tool before the expensive one, and knows which decompiler to retry with
Two tools support that bundle today. Everything else is
MCP-only.
Claude Code
bash
claude plugin marketplace add hqkh4nh/dejared-mcp
claude plugin install dejared@dejared-mcp-marketplace
Inside a session, the same commands work as /plugin marketplace add ... and
/plugin install .... If the install summary says Run /reload-plugins to activate, run it.
The -- matters: everything after it is the server's launch command.
Or edit ~/.codex/config.toml (global) or .codex/config.toml (project):
toml
[mcp_servers.dejared]command = "npx"args = ["-y", "dejared-mcp"]
# Only if Java is not on your PATH[mcp_servers.dejared.env]DEJARED_JAVA_PATH = "/path/to/java"
VS Code (GitHub Copilot): uses servers, not mcpServers
The npm package is a thin Node.js wrapper. On first run it:
Checks the platform cache directory for a cached JAR matching the current version.
Linux: $XDG_CACHE_HOME/dejared-mcp (defaults to ~/.cache/dejared-mcp)
macOS: ~/Library/Caches/dejared-mcp
Windows: %LOCALAPPDATA%\dejared-mcp
Downloads the JAR from GitHub Releases if not cached.
Spawns java -jar with stdio inherited for MCP transport.
The server communicates over stdio using the Model Context Protocol.
FAQ and Troubleshooting
Q: Java is installed but the server cannot find it.
Set the DEJARED_JAVA_PATH environment variable in your MCP
configuration. See Custom Java Path.
Q: The server fails to start with a permission error.
Ensure that the cached JAR file is readable. The cache location
depends on your platform. See How It Works for
the cache directory paths.
Q: Decompilation times out or returns an error.
Some classes are difficult to decompile. Try a different engine
by specifying vineflower or procyon in the dejared_decompile_class
tool. The default timeout is 30 seconds and can be adjusted via
dejared.security.decompile-timeout-seconds.
Q: Which Java version do I need?
Java 17 or later. A JRE is sufficient; you do not need a full JDK.
Q: Can I run the server without Node.js?
Yes. Download the JAR from GitHub Releases and run it directly
with java -jar. See the "Pure Java" section under
Install as an MCP server.
Contributing
Contributions are welcome. Please follow these guidelines:
Fork the repository and create a feature branch from master.
Ensure your changes compile and pass existing tests.
Write clear commit messages describing the purpose of each change.
Open a pull request against master with a description of what
the change does and why.
Every manifest listed under Project Structure carries a
version field, and CI fails the build if any of them drifts from
package.json. Bump them together.
Project Structure
code
dejared-mcp/
βββ bin/ # Node.js CLI entry point
βββ lib/ # Node.js wrapper (JAR download and process management)
βββ java-mcp/ # Java MCP server (Spring Boot, Gradle)
β βββ src/
βββ skills/ # Agent skills, shared by every plugin manifest below
βββ .mcp.json # MCP server definition, shared the same way
βββ .claude-plugin/ # Claude Code plugin + marketplace manifests
βββ .codex-plugin/ # Codex plugin manifest
βββ .agents/plugins/ # Codex marketplace manifest
βββ package.json # npm package manifest
βββ server.json # MCP Registry manifest
Building from Source
bash
cd java-mcp
./gradlew build
Reporting Issues
Open an issue on GitHub Issues
with steps to reproduce the problem, your Java version, and your
Node.js version.
Third-Party Licenses
This project uses the following open-source libraries: