🔐 Advanced JWT Analysis & Security Tool 🔐
100% Client-Side • Your Data Remains Yours
Documentation GitHub

JWT Token

Header


                            

Payload


                            

Signature


                            

Security Analysis

⚔️ JWT Attack Platform

Guided attack generation for comprehensive JWT security testing

Select Attack Category

Algorithm Attacks

🚫
None Algorithm Bypass

Remove signature verification by setting algorithm to "none"

Easy High Impact
🔄
Algorithm Confusion

Convert asymmetric algorithms (RS256/RS384/RS512) to symmetric (HS256/HS384/HS512) using public key as HMAC secret

Medium High Impact

Header Injection Attacks

💉
Kid Parameter Injection

SQL injection, path traversal, command injection via kid parameter

Medium High Impact
🌐
JKU/X5U Manipulation

URL manipulation attacks for key injection and SSRF

Hard Critical
🔑
JWK Header Injection

Embed malicious public key directly in JWT header

Medium Critical

Payload Manipulation

⬆️
Privilege Escalation

Role and permission bypass through payload manipulation

Medium Critical
🎭
Claim Spoofing

Manipulate user identity and authorization claims

Easy High Impact

Configure Attack

Generated Attack Payloads

JWT Token for Bruteforce

Bruteforce Method

Using the default jwt secrets list file containing common JWT secrets and passwords.

Results

0%
Ready to start

JWT Token to Edit

Header

Payload

Signature Options

Generated JWT


                        

Verify Signature

Header

Payload

Add Common Claims:

Signature Options

Generated JWT