JWT attack methodology for authorized pentesting - alg:none and RS256→HS256 confusion, weak-secret brute force, kid/jku/jwk header injection, JWS/JWE confusion, and validation gaps.
---
name: Offensive JWT
description: JWT attack methodology for authorized penetration testing - algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid/jku/jwk/x5u header injection, JWKS cache poisoning, and JWS/JWE confusion. Use when testing JWT auth, hunting auth bypass via token manipulation, or evaluating JWT implementation security.
---
A JWT attack checklist for authorized offensive security engagements only. Work through steps in order against the in-scope target and track what you've covered.
## Workflow
1. Identify JWT usage: inspect `Authorization: Bearer` headers, cookies, and local/session storage for `eyJ...` tokens; decode and note header params (`kid`, `jku`, `jwk`, `x5u`).
2. Test algorithm bypass: `alg:none` and case variants, and RS256→HS256 confusion (using the RSA public key as the HMAC secret).
3. Brute-force weak/guessable HMAC secrets.
4. Probe header injection: SQLi/path traversal via `kid`, inline fake `jwk`, attacker-controlled `jku`/`x5u` (SSRF), and JWKS cache poisoning.
5. Check broken validation: tokens accepted without signature check, expired tokens accepted, and missing `iss`/`aud`/`exp` checks; consider JWS/JWE confusion and token-binding (DPoP/mTLS) replay.
Reference tooling: jwt_tool (ticarpi/jwt_tool). Only test assets you are authorized to assess.
Full skill & source: https://github.com/SnailSploit/Claude-Red/tree/main/Skills/auth/offensive-jwt