JWT Security Testing

Installation
SKILL.md

JWT Security Testing

Purpose

Identify and exploit vulnerabilities in JSON Web Token (JWT) implementations, including algorithm confusion attacks, secret key cracking, signature bypass, and claim manipulation. JWTs are widely used for authentication and authorization, making them high-value targets for security testing.

Prerequisites

Required Tools

  • jwt_tool (Python JWT manipulation)
  • Burp Suite with JWT extensions
  • Hashcat or John the Ripper for cracking
  • Python with PyJWT library
  • jwt.io for decoding
Installs
GitHub Stars
31
First Seen
JWT Security Testing — zebbern/secops-cli-guides