JWT Vulnerability Check

Decode a JWT and test it for alg=none and weak HMAC signing secrets, entirely in your browser.

Input

Related tools

What it does

Decodes any JSON Web Token into its header and payload, spells out the registered claims (issuer, subject, audience, expiry) with human readable dates, and tests the token for two classic weaknesses: the alg=none trick that leaves a token unsigned, and HMAC secrets that are weak or guessable. Give it a secret or a wordlist and it recomputes the HS256, HS384, or HS512 signature to tell you whether the token verifies. Every check runs on tokens you are authorized to test.

How to use it

Paste a token in the header.payload.signature form. The decoded claims and any alg=none finding appear immediately. To test an HMAC secret, type it into the signing secret field, or paste a list of candidate secrets one per line; the tool also tries a built in list of common secrets and reports a match as a critical finding. Set a time override to check expiry against a fixed moment instead of the live clock.

Why this one

The usual move is to paste a token into jwt.io or an online cracker, but a real token is a live credential and those sites receive it on their servers. Here the token never leaves your device, so there is nothing to log, retain, or leak. No sign in, no rate limits, and it keeps working offline.

FAQ
Is it safe to paste a real token?
The token stays in your browser and is never sent anywhere, so pasting one here is far safer than pasting it into an online decoder. Even so, treat anything you have pasted into any tool as potentially exposed and rotate or revoke it afterward as good hygiene.
What is alg=none?
alg=none is a JWT header that declares the token has no signature. A server that honors it will accept a token with any payload, so an attacker can forge an admin token by editing the claims. If this tool flags alg=none, make sure your backend rejects unsigned tokens.
Can it crack strong secrets?
No. It only catches weak, common, or guessable HMAC secrets by testing a small built in list plus any wordlist you provide. A long random secret will not be found, which is exactly why you should use one.

Keyboard shortcuts: press ? anywhere on this page to see them.