Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/hahwul/jwt-hack
Password CrackingVulnerability ScannersEncryption/Decryption ToolsPayload GenerationWeb SecurityPenetration Testing
GitHubhahwul/jwt-hack

jwt-hack

JSON Web Token Hack Toolkit

View Repository
1.0k121281 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website
jwt-hack

JSON Web Token Hack Toolkit


A high-performance toolkit for testing, analyzing and attacking JSON Web Tokens.

Installation

Cargo

cargo install jwt-hack

Homebrew

brew install jwt-hack

Snapcraft (Ubuntu)

sudo snap install jwt-hack

Chocolatey (Windows)

choco install jwt-hack

From source

git clone https://github.com/hahwul/jwt-hack
cd jwt-hack
cargo install --path .

Docker images

GHCR

docker pull ghcr.io/hahwul/jwt-hack:latest

Docker Hub

docker pull hahwul/jwt-hack:v2.6.0

Features

ModeDescriptionSupport
EncodeJWT/JWE EncoderSecret based / Key based / Algorithm / Custom Header / DEFLATE Compression / JWE
DecodeJWT/JWE DecoderAlgorithm, Issued At Check, DEFLATE Compression, JWE Structure
VerifyJWT VerifierSecret based / Key based (for asymmetric algorithms)
CrackSecret CrackerDictionary Attack / Brute Force / DEFLATE Compression
PayloadJWT Attack Payload Generatornone / jku&x5u / alg_confusion (signed via --public-key) / kid & claim injection / claims tampering / signature malleability / JWE probes / x5c / cty
ScanVulnerability ScannerAutomated security checks for common JWT vulnerabilities
ServerAPI ServerRun API Server Mode (http://localhost:3000)
MCPModel Context Protocol ServerAI model integration via standardized protocol

Basic Usage

Decode a JWT

You can decode both regular and DEFLATE-compressed JWTs. The tool will automatically detect and decompress compressed tokens.

jwt-hack decode eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0In0.CHANGED
jwt-hack decode COMPRESSED_JWT_TOKEN

Decode a JWE

Decode JWE (JSON Web Encryption) tokens to analyze their structure. The tool automatically detects JWE format (5 parts) and displays the encryption details.

# Decode JWE token structure
jwt-hack decode eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0..ZHVtbXlfaXZfMTIzNDU2.eyJ0ZXN0IjoiandlIn0.ZHVtbXlfdGFn

# Shows JWE header, encrypted key, IV, ciphertext, and authentication tag

Encode a JWT

jwt-hack encode '{"sub":"1234"}' --secret=your-secret

Encode a JWT with DEFLATE Compression

You can use the --compress option to apply DEFLATE compression to the JWT payload.

jwt-hack encode '{"sub":"1234"}' --secret=your-secret --compress
# With Private Key
ssh-keygen -t rsa -b 4096 -E SHA256 -m PEM -P "" -f RS256.key
jwt-hack encode '{"a":"z"}' --private-key RS256.key --algorithm=RS256

Encode a JWE

Create JWE (JSON Web Encryption) tokens for testing encrypted JWT scenarios.

# Basic JWE encoding
jwt-hack encode '{"sub":"1234", "data":"encrypted"}' --jwe --secret=your-secret

# JWE tokens are encrypted and can only be decrypted with the proper key
jwt-hack encode '{"sensitive":"data"}' --jwe

Verify a JWT

Checks if a JWT's signature is valid using the provided secret or key.

# With Secret (HMAC algorithms like HS256, HS384, HS512)
jwt-hack verify YOUR_JWT_TOKEN_HERE --secret=your-256-bit-secret

# With Private Key (for asymmetric algorithms like RS256, ES256, EdDSA)
jwt-hack verify YOUR_JWT_TOKEN_HERE --private-key path/to/your/RS256_private.key

Crack a JWT

Dictionary and brute force attacks also support JWTs compressed with DEFLATE.

# Dictionary attack
jwt-hack crack -w wordlist.txt JWT_TOKEN
jwt-hack crack -w wordlist.txt COMPRESSED_JWT_TOKEN

# Bruteforce attack
jwt-hack crack -m brute JWT_TOKEN --max=4
jwt-hack crack -m brute COMPRESSED_JWT_TOKEN --max=4

Generate payloads

jwt-hack payload JWT_TOKEN --jwk-attack evil.com --jwk-trust trusted.com

Scan for vulnerabilities

Automatically scan JWT tokens for common security issues and vulnerabilities.

# Full scan including weak secret detection and payload generation
jwt-hack scan JWT_TOKEN

# Skip secret cracking for faster results
jwt-hack scan JWT_TOKEN --skip-crack

# Skip payload generation
jwt-hack scan JWT_TOKEN --skip-payloads

# Use custom wordlist for weak secret detection
jwt-hack scan JWT_TOKEN -w custom_wordlist.txt

# Limit secret testing attempts
jwt-hack scan JWT_TOKEN --max-crack-attempts 50

The scan command checks for:

  • None algorithm vulnerability: Detects if the token accepts unsigned tokens
  • Weak secrets: Tests against common passwords (customizable with wordlist)
  • Algorithm confusion: Identifies tokens vulnerable to RS256->HS256 attacks
  • Token expiration issues: Checks for missing or improper expiration claims
  • Missing security claims: Verifies presence of recommended JWT claims
  • Kid header injection: Detects potential SQL/path injection vulnerabilities
  • JKU/X5U header attacks: Identifies URL spoofing attack vectors

Server (REST API)

Start a local REST API for automation and integrations. To require authentication, use --api-key and include X-API-KEY in requests.

# Start on localhost:3000 with API key protection
jwt-hack server --api-key your-api-key

# Example request (must include X-API-KEY when --api-key is set)
curl -s http://127.0.0.1:3000/health -H 'X-API-KEY: your-api-key'

MCP (Model Context Protocol) Server Mode

jwt-hack can run as an MCP server, allowing AI models to interact with JWT functionality through a standardized protocol.

# Start MCP server (communicates via stdio)
jwt-hack mcp

The MCP server exposes the following tools:

ToolDescriptionParameters
decodeDecode JWT tokenstoken (string)
encodeEncode JSON to JWTjson (string), secret (optional), algorithm (default: HS256), no_signature (boolean)
verifyVerify JWT signaturestoken (string), secret (optional), validate_exp (boolean)
crackCrack JWT tokenstoken (string), mode (dict/brute), chars (string), max (number)
payloadGenerate attack payloadstoken (string), target (string), jwk_attack (optional), jwk_protocol (default: https), public_key (optional PEM/path for signed alg-confusion)

Example MCP Usage

The MCP server is designed to be used by AI models and MCP clients. Each tool accepts JSON parameters and returns structured responses.

Download Tool