jwt-attacks - Test JWT authentication and authorization vulnerabilities
Exploits JWT signature, algorithm, key-management, and claim-handling vulnerabilities during authorized penetration testing.
Tags
Updated: 2026-09-29JWTweb securityauthenticationauthorizationpenetration testingtoken forgerykey confusionheader injection
Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Locate JWT tokens
- Decode JWT components
- Identify signing algorithms
- Test algorithm-none bypasses
- Test null signatures
- Assess weak HMAC secrets
- Save JWT hashes
- Forge signed tokens
- Test key confusion
- Test header injections
- Extract public keys
- Record engagement evidence
- Read engagement state
Inputs
- Target application
- JWT token
- Target URL
- RSA public key
- Engagement directory
- Engagement state
Outputs
- Forged JWT tokens
- JWT hash files
- Public key files
- Evidence files
- Activation messages
- Engagement summaries
- Confirmed vulnerability findings
Requirements
- Explicit written authorization
- jwt_tool
- Hashcat
- Burp Suite with JWT Editor
- OpenSSL for key extraction
- State MCP server
