jwt_tool
Swiss-army knife for JWTs: decode, tamper claims, and test the classic attacks - alg:none, key confusion (RS→HS), weak-secret cracking, and kid injection.
Tags: jwt, auth, tampering
- Category
- inject
- Maintenance signal
- maintained
Project repository · Documentation
Use this when: JWT. Decode the token and record what the server actually checks.
Install
git
git clone https://github.com/ticarpi/jwt_tool && cd jwt_tool && pip install -r requirements.txtCommand templates
Run all attacks
python3 jwt_tool.py {token} -M atCrack weak secret
python3 jwt_tool.py {token} -C -d {wordlist}