JWT Attack Simulator

Paste a JWT and simulate alg=none, weak-secret brute force, and kid header injection attacks. See exactly what an attacker could forge.

Free

Token input

Tokens are processed in-memory and discarded after the response is returned.

Results

Paste a JWT and run a simulation to see exploit outcomes.

Related tools