jwt-cracker - Test JWT signature and claim validation
Analyzes JWTs and tests algorithm confusion, weak secrets, header injections, claim tampering, and validation weaknesses.
Tags
Updated: 2026-09-28Capabilities
Typical Outputs
What this skill does
- Decode JWT headers and claims
- Test alg:none acceptance
- Test algorithm confusion
- Brute-force weak HMAC secrets
- Test kid injections
- Test jku and x5u injections
- Test embedded jwk trust
- Tamper with token claims
- Check expiration validation
- Check audience and issuer validation
- Test token context reuse
- Document successful findings
Inputs
- JWT token
- Target API or web application
- Public key or JWKS endpoint
- Secret wordlist
- Attacker-controlled JWKS URL
Outputs
- Decoded JWT data
- Forged JWT tokens
- API response results
- JWT vulnerability findings
Requirements
- Python 3
- JWT library support
- Cryptography library support
- Optional hashcat, John, or jwt_tool
