Skip to content

[addtool] Tool JWTAuditor #2032

Description

@dr34mhacks

Link to the tool: https://... (minimum 1 required):
[link]https://github.com/dr34mhacks/jwtauditor[/link]

List of tags separated by comma: tag1,tag2,tag3... (required):
[tags]jwt,authentication,authorization,web-security,api-security,token-analysis[/tags]

Short description of the tool (required, maximum 100 characters):
[short_descr]Security testing tool to analyze JWTs for weak secrets, misconfigs, and auth flaws[/short_descr]

A bigger description (optional, but nice to have):
[long_descr] Jwtauditor is an offensive security tool designed to analyze JSON Web Tokens (JWTs) for common implementation and configuration weaknesses. It helps identify issues such as weak or guessable signing secrets, insecure or missing claims, algorithm misuse, and structural flaws that may lead to authentication bypass or privilege escalation. The tool is intended for penetration testers, bug bounty hunters, and security engineers performing web and API security assessments where JWT-based authentication or authorization is in use. Its output focuses on practical exploitability rather than simple token decoding.
[/long_descr]

A link or an attached image (minimum 1 required):
[image] https://jwtauditor.com/img/decoder.jpg [/image]

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions