jwtforge. Attacker-minded, 100% client-side JWT toolkit — decode, audit & forge tokens. Generates alg:none, key-confusion, kid-injection & brute-force attacks with ready-to-run curl/Burp/nuclei exports. The security alternative to jwt.io.

github.com/devploit/jwtforge

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.