{"repo":"chawdamrunal/JWTLens","free":true,"listed":false,"github":"https://github.com/chawdamrunal/JWTLens","clone":"git clone https://github.com/chawdamrunal/JWTLens.git","description":"JWTLens - Burp Suite extension for automated JWT security testing. 62 checks: passive scanning, algorithm confusion, signature bypass, KID injection, weak secret brute force, and a built-in JWT Forge tab. Works automatically as you browse.","language":"Java","stars":55,"topics":["bug-bounty","burp-extensions","burpsuite","cybersecurity","jwt","jwt-decode","jwt-security","owasp","security-scanner","security-tools"],"license":null,"category":"security-tools","readme_excerpt":"JWTLens Comprehensive JWT Security Scanner for Burp Suite JWTLens is a Burp Suite extension that automatically detects and tests JSON Web Tokens (JWTs) for security vulnerabilities. It performs 56 security checks covering the complete JWT attack surface — from passive analysis of token configuration to active exploitation of signature bypasses, algorithm confusion, header injection, and more. JWTLens is a JWT decoder and security testing tool for analyzing JSON Web Tokens. It helps detect vulnerabilities like algorithm confusion, signature bypass, and weak validation. JWTLens adds two dedicated tabs in Burp Suite's top bar: JWTLens (findings dashboard) and JWT Forge (live token editor and signer). It also passively extracts secrets and keys from JavaScript files and API responses to supercharge its active attacks. Why JWTLens? Most JWT testing tools either require manual effort or only cover a handful of checks. JWTLens runs automatically in the background as you browse, catching JWT misconfigurations the moment they appear in your proxy traffic. When you want to go deeper, the active scanner tests every known JWT attack vector against the server with a single right click. Compared to existing JWT extensions, JWTLens adds: - Full passive scanning (no other extension does this) - JWT Forge tab — a live jwt.io-style editor with signing built into Burp - Secret Extractor — passively finds hardcoded secrets and keys in JS/JSON/HTML responses - Proper JWKS parsing — fetches the re","default_branch":null,"files":null,"tree":[],"storefront":"/r/chawdamrunal","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/chawdamrunal/JWTLens/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}