JWT
Signature Attacks
Key Management
JWE
JWTF – JWT Forgery
developed by
Token Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwczovL2lzc3Vlci5leGFtcGxlIiwic3ViIjoiQ29ubmk0MDQiLCJhdWQiOiJodHRwczovL2hhY2ttYW5pdC5kZSIsImlhdCI6MTY4NDg0ODYwMCwiZXhwIjoxNjg0ODYwNDgwLCJub25jZSI6Ikh0UnMxODQ4LVQwUjMxNDEtVmZMIn0.yVRRzN5yOxNrzawTUr1eUi7fwGitsBk6I5ZfYw9CvQA
Header
Payload
Signature is
Valid
JSON Controls
Valid
Raw
Beautify
Minify
Signature Controls
Decode
Encode/Sign
Verify Signature
Enable automatic signing
Algorithm:
none
HS256
HS384
HS512
RS256
RS384
RS512
ES256
ES384
ES512
PS256
PS384
PS512
super-secret-string
Private Key
Public Key
Paste your JWT here:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwczovL2lzc3Vlci5leGFtcGxlIiwic3ViIjoiSm9obiBEb2UiLCJhdWQiOiJleGFtcGxlLWNsaWVudCIsImlhdCI6MTc1NTgxMzYwMCwiZXhwIjoxNzU1ODk5OTk5fQ.p6XQX1WitrvfCMPl46hxWKehJufDZCrNHFrVfTD0VV8
Import from JWT View
Generate Manipulated Tokens
Select Vulnerabilities to Test:
Select All
Select All Without User Interaction
Token Mapping Overview
ID
Token
Description
Variant
Attack
Key Management
Key Generation
Algorithm:
HS256
HS384
HS512
RS256
RS384
RS512
PS256
PS384
PS512
RSA-OAEP
RSA-OAEP-256
ES256
ES384
ES512
A128KW
A192KW
A256KW
A128GCMKW
A192GCMKW
A256GCMKW
Key Size:
2048 bit
3072 bit
4096 bit
Key Length:
32 bytes (256 bit)
48 bytes (384 bit)
64 bytes (512 bit)
Generate as Hex
Generate as Base64
Generate Key
Generated Key:
Copy
Private Key (PEM):
Copy
Public Key (PEM):
Copy
Private Key (JWK):
Copy
Public Key (JWK):
Copy
Key Conversion
Conversion Direction:
PEM → JWK
JWK → PEM
PEM Key Input:
Algorithm (for JWK):
RS256
RS384
RS512
PS256
PS384
PS512
ES256
ES384
ES512
JWK Input:
Convert
Conversion Result:
Copy Result
Local Storage Management
Automatically save generated keys to local storage
Save Current Keys
Load Saved Keys
Clear All Saved Keys
Saved Keys:
JWE Tool
Token Input
Header
Payload
Base64
Private Key
Private Key
PBKDF2 Iterations:
Salt (Base64):
Key Encryption Algorithm:
RSA-OAEP
RSA-OAEP-256
A128KW
A192KW
A256KW
dir
A128GCMKW
A192GCMKW
A256GCMKW
Content Encryption Algorithm:
A128CBC-HS256
A192CBC-HS384
A256CBC-HS512
A128GCM
A192GCM
A256GCM
Decrypt
Encrypt