{"repo":"rishuranjanofficial/JWTweak","free":true,"listed":false,"github":"https://github.com/rishuranjanofficial/JWTweak","clone":"git clone https://github.com/rishuranjanofficial/JWTweak.git","description":"Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.","language":"Python","stars":103,"topics":["jwt","jwt-tokens","automation","vulnerability-assessment","python","jwt-algorithm","security-enthusiasts","application-security","bugbounty","appsec"],"license":null,"category":"auth-billing-email","readme_excerpt":"JWTweak Introduction JWTweak is a guided, fully-offline JWT security-testing toolkit. It detects the algorithm of an input token, analyses it for risky configuration, recommends the attacks that fit, and walks you through each one — no flags to memorise. Just run it: Paste a token, and JWTweak decodes it, shows a risk report, and presents a smart menu with the relevant attacks highlighted. Every attack runs 100% offline — nothing is ever sent over the network. ⚠️ For authorised security testing and research only. Download Method Command / Link --- --- Clone the full project (recommended) git clone https://github.com/rishuranjanofficial/JWTweak.git Direct script download JWTweak.py Latest release Releases page Highlights - Zero flags. Run it, paste a token, follow the menu. Nothing to look up. - Fully offline. No attack makes a network call. jku / x5u artifacts are generated locally, and JWTweak can even spin up a built-in local web server so you can host them without any external service. - Smart & guided. Auto-decodes, runs a risk analysis, and marks the attacks that make sense for your token as recommended . - Polished TUI via rich — panels, syntax-highlighted JSON, a risk table, and a live cracking progress bar. Falls back to a clean plain-text UI automatically if rich isn't installed. Attack coverage Area What it does --- --- Recon decode + risk analysis Signature / algorithm alg:none variants, algorithm confusion (RS/ES → HMAC), re-sign with HS/RS/PS/ES/EdDSA , signature","default_branch":null,"files":null,"tree":[],"storefront":"/r/rishuranjanofficial","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rishuranjanofficial/JWTweak/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}