← The Arsenal
TOOL · LIVE
JWT Forensics 🪪
Decode + vulnerability scan + signature demo.
Paste any JWT token. We decode the header, payload, and signature. Scan for common vulnerabilities like RS256/HS256 confusion, weak algorithms, expired claims, and show the signature mechanics step-by-step.