Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Start with PortSwigger Web Security Academy’s JWT lessons and deliberately vulnerable labs, then practice inspecting and changing tokens with Burp Suite’s JWT Editor. Add jwt_tool for standalone command-line work or OWASP PTK when you want to examine JWTs in a live browser session. Keep hands-on testing in the labs unless you have explicit permission to assess another system.

What to learn before testing JWTs

A JSON Web Token (JWT) commonly carries a header and payload encoded as base64url JSON, followed by a signature. Decoding the first two sections reveals their contents; it does not prove that the token is authentic. The receiving application must verify the signature and validate the token appropriately before trusting its claims. PortSwigger’s JWT learning material introduces token structure and several implementation flaws, including broken signature verification, weak signing secrets, unsafe handling of header parameters, and algorithm confusion.

These are different failure modes, not interchangeable tricks. Testing asks whether an application’s actual validation behavior is flawed; editing a claim or decoding a token alone does not establish a vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practice the concepts in Web Security Academy

PortSwigger Web Security Academy is the best starting point in this workflow because its JWT topic combines explanations with intentionally vulnerable labs. Work through the lesson material, then use the labs to see how specific implementation weaknesses affect a target designed for practice. The exercises cover selected scenarios, so completing them is not a full assessment of a real application.

Keep practice within Academy labs or systems you own or are explicitly authorized to test. A lab demonstrates mechanics in a controlled setting; it does not grant permission to test a public service.

Inspect and edit tokens with Burp Suite

Burp’s documented workflow pairs Inspector with the JWT Editor extension. Inspector decodes token sections, while JWT Editor lets you edit header or payload JSON and re-sign a token using a selected key. Burp documentation describes this workflow for both Community and Professional editions. Some extension-related capabilities, including Collaborator payload functionality, require Professional; those features are not necessary to begin the lab workflow.

  1. Open a JWT lab and route its traffic through Burp. Use an Academy lab as the target rather than an unrelated service.
  2. Capture a request containing a token. Select the request in Burp and inspect the JWT in the message editor’s Inspector panel.
  3. Review the header and payload. Note which claims and header parameters the application uses, without treating decoded values as trusted.
  4. Use JWT Editor for a controlled change. Edit a header or claim and, where the exercise calls for it, sign with a selected key. Send the request to the lab and observe whether the application accepts it.
  5. Interpret the response in context. A changed token matters only if the application accepts it and its behavior demonstrates an authorization or integrity problem.

Burp’s current JWT documentation, updated October 7, 2026, is at JWTs in Burp Suite. For optional automated checks within Burp, PortSwigger’s third-party JWT Scanner BApp listing describes detection and scans for several JWT weaknesses. Its listing identifies version 2.1.0, last updated May 29, 2025, and disclaims PortSwigger warranty; check compatibility before relying on it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Add a command-line option with jwt_tool

jwt_tool is a Python toolkit for validating, scanning, forging, and tampering with JWTs. Its project repository also points to a playbook that lays out a repeatable testing methodology. It suits readers who want token work outside Burp’s graphical workflow, but tool output cannot substitute for understanding how the application validates a token.

Use the project’s repository for the toolkit and its linked testing playbook. Follow the project’s usage guidance and run tests only against labs or targets covered by explicit authorization; its playbook warns that testing services without ownership or permission may be unlawful.

Use OWASP PTK for browser-session coverage

OWASP PTK is an open-source browser extension that can inspect and replay traffic and test JWTs in the live browser session. This can help when you want to work alongside an authenticated browser workflow rather than move every request into a separate proxy interface. OWASP describes PTK as complementary to full interception proxies and other testing tools, not a replacement for them.

Keep weak-secret exercises inside a lab

PortSwigger’s weak signing key lab demonstrates how a weak secret can undermine JWT integrity and recommends Hashcat for the exercise. Treat this as a contained learning scenario: recovering or guessing a real service’s signing secret without authorization is not a safe extension of the lab.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the tool that fits the task

Option Best fit What it supports Context and limits
Web Security Academy JWT topic Learning fundamentals and practicing Explanations and deliberately vulnerable labs covering selected JWT implementation flaws. Lab results do not amount to a complete real-application assessment.
Burp Suite with JWT Editor Inspecting, editing, and re-signing tokens in intercepted requests Inspector decodes token sections; JWT Editor edits JSON and signs with a selected key. The documented workflow is available in Community and Professional; some extension features, including Collaborator payload functionality, require Professional.
jwt_tool Standalone command-line token work Validation, scanning, forging, and tampering, with a project playbook for methodology. It does not replace analysis of the target application’s validation behavior.
OWASP PTK JWT testing within a browser workflow Traffic inspection, replay, and JWT testing in the live browser session. OWASP positions it as a complement to full interception proxies and other tools.
JWT Scanner BApp Automated checks inside Burp Automatic JWT detection and scans for several JWT weaknesses, as described in its listing. Third-party extension; listing states version 2.1.0, updated May 29, 2025, and no PortSwigger warranty. Verify compatibility.

These options support different workflows rather than a proven ranking. The cited materials do not provide a controlled head-to-head comparison of their detection accuracy or speed.

A practical beginner workflow

  1. Learn the token model. Read the Academy JWT topic and distinguish decoding from signature verification and server-side validation.
  2. Complete the relevant labs. Practice the flaw classes the lessons cover, including weak secrets, header handling, and algorithm confusion.
  3. Repeat the exercise in Burp. Inspect a lab request, make a controlled token change with JWT Editor, and judge success by the application’s response.
  4. Choose one extension to your workflow. Try jwt_tool for standalone command-line work or PTK for browser-session coverage; use the Burp scanner only after checking its current compatibility.
  5. Stay within scope. For any target beyond a training lab, get explicit authorization and follow the agreed testing boundaries.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.