vulns.co
/
GKData.io MCP

Back to Library

jwt_tool

Swiss-army knife for JWTs: decode, tamper claims, and test the classic attacks - alg:none, key confusion (RS→HS), weak-secret cracking, and kid injection.

Tags: jwt, auth, tampering

Category
inject
Maintenance signal
maintained

Project repository · Documentation

Use this when: JWT. Decode the token and record what the server actually checks.

Install

git

git clone https://github.com/ticarpi/jwt_tool && cd jwt_tool && pip install -r requirements.txt

Command templates

Run all attacks

python3 jwt_tool.py {token} -M at

Crack weak secret

python3 jwt_tool.py {token} -C -d {wordlist}

Related tools