Skip to main content

vamp-jwt-audit

Python 3.9+ Platform License MIT VampSecure Labs CI

Overview

vamp-jwt-audit is a JWT (JSON Web Token) security auditor that tests tokens for the full range of documented attack classes: alg=none bypass, RS256-to-HS256 algorithm confusion, HMAC brute-force against a 200+ entry built-in wordlist, header injection attacks (jku, x5u, jwk, kid), and claims-level security issues. It accepts tokens from the command line, a file, or standard input — making it easy to slot into proxies, CI pipelines, or capture-the-flag workflows. The optional cryptography library unlocks the RS256-to-HS256 attack when a public key is supplied.

Features

  • Six-phase attack sequence: decode without verification, header analysis, claims analysis, craft alg=none token, HMAC brute-force, RS256→HS256 confusion
  • Built-in wordlist with 200+ common secrets including framework defaults, Docker/Kubernetes defaults, and the empty string
  • Header injection checks: alg=none (CRITICAL), jku/x5u key URL injection (CRITICAL), inline jwk (CRITICAL), kid path traversal and SQL injection patterns (CRITICAL)
  • Claims security checks: missing exp (HIGH), expired token (MEDIUM), TTL > 24 hours (LOW), nbf in future (MEDIUM), missing iss/aud (LOW), privileged role claims (HIGH), PII in payload (MEDIUM)
  • RS256→HS256 confusion attack: forges a valid-looking HS256 token signed with the RSA public key (requires --pubkey and cryptography)
  • Custom wordlist support (--wordlist) with automatic fallback to the built-in list
  • Supports single token (--token), file of tokens (--file), and stdin pipeline mode (--stdin)
  • Export to Console (Rich panels), JSON, and HTML (dark-theme)

Requirements

  • Python 3.9 or later
  • rich >= 13.7.0
  • Optional: cryptography >= 41.0 — required for --pubkey (RS256→HS256 confusion attack)

Installation

pip install vamp-jwt-audit
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-jwt-audit
git clone https://github.com/belky-me/vamp-jwt-audit.git
cd vamp-jwt-audit
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt
# For RS256→HS256 attack support:
pip install cryptography

Usage

python3 vamp_jwt_audit.py --help
usage: vamp_jwt_audit.py [-h]
  Token source (mutually exclusive):
    --token JWT, -t JWT
    --file FILE, -f FILE
    --stdin

  Attack options:
    --wordlist FILE, -w FILE
    --pubkey FILE
    --no-bruteforce

  Output:
    --json FILE
    --html FILE
    --quiet
    --client CLIENT --engagement ENGAGEMENT --auditor AUDITOR
    --report-scope SCOPE --report-html FILE --report-pdf FILE

vamp-jwt-audit — JWT Security Auditor (VampSecure Labs)

Examples

# Audit a single token passed directly
python3 vamp_jwt_audit.py --token eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

# Read token from file
python3 vamp_jwt_audit.py --file captured_token.txt

# Pipe a token from another tool
cat token.txt | python3 vamp_jwt_audit.py --stdin

# Use a custom wordlist for HMAC brute-force
python3 vamp_jwt_audit.py --token <JWT> --wordlist /path/to/secrets.txt

# Run RS256→HS256 confusion attack using a captured public key
python3 vamp_jwt_audit.py --token <JWT> --pubkey server_pubkey.pem

# Skip brute-force (faster static analysis only)
python3 vamp_jwt_audit.py --token <JWT> --no-bruteforce

# Export findings to JSON and HTML
python3 vamp_jwt_audit.py --token <JWT> --json results.json --html report.html

# Generate client-ready engagement report
python3 vamp_jwt_audit.py --file tokens.txt \
    --client "Acme Corp" --engagement "JWT Implementation Review Q3 2026" \
    --auditor "J. Smith" --report-html client_report.html --report-pdf client_report.pdf

CLI Reference

Flag Default Description
--token / -t JWT — JWT token string (mutually exclusive with --file/--stdin)
--file / -f FILE — File containing one or more JWT tokens
--stdin — Read token from standard input
--wordlist / -w FILE built-in (200+) Custom wordlist for HMAC brute-force
--pubkey FILE — RSA/EC public key PEM file for RS256→HS256 confusion
--no-bruteforce off Skip HMAC brute-force phase
--json FILE — Export results to JSON
--html FILE — Export dark-theme HTML report
--quiet off Suppress banner
--client TEXT — Client name for VSL engagement report
--engagement TEXT — Engagement title for VSL engagement report
--auditor TEXT — Auditor name for VSL engagement report
--report-scope TEXT — Scope description for VSL engagement report
--report-html FILE — Export unified VSL client report (HTML)
--report-pdf FILE — Export unified VSL client report (PDF, requires fpdf2)

Output Formats

Format Flag Description
Console (default) Rich panels with decoded header/payload, attack results, and severity ratings
JSON --json FILE Machine-readable full result set including forged token strings
HTML --html FILE Dark-theme standalone report
Client HTML --report-html FILE Unified VampSecure Labs engagement report
Client PDF --report-pdf FILE PDF version of the VSL client report

Exit Codes

Code Meaning CI/CD Behavior
0 No critical or high findings Pipeline passes
1 High-severity findings detected Pipeline fails — review required
2 Critical-severity findings detected Pipeline fails — immediate action required

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-jwt-audit is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.3.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-jwt-audit 1.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-jwt-audit 1.4.0
File Size Uploaded
vamp_jwt_audit-1.4.0.tar.gz 53.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-jwt-audit 1.4.0
File Interpreter ABI Platform
vamp_jwt_audit-1.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 102.9 kB

Release files / vamp_jwt_audit-1.4.0.tar.gz

Download URL vamp_jwt_audit-1.4.0.tar.gz
Size 53.3 kB
Tags Source
SHA-256 checksum
How to use checksums
b2c4b8b9372c9cc187eab02bdc5def52b6b289ae6eb08f10fe588661315f1ae6
BLAKE2b-256 checksum
How to use checksums
a7a13f4c7cfd57344d30786980838e518044e76a2fc2fedf749bb7cd772d1bf5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / vamp_jwt_audit-1.4.0-py3-none-any.whl

Download URL vamp_jwt_audit-1.4.0-py3-none-any.whl
Size 49.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3d6a60ea1ed19cbd684360f33aa1a7c15318ce39b7ec5f1cec9b11eafcaec5db
BLAKE2b-256 checksum
How to use checksums
77e90032296d9db462394e580abbb2828a01d390d956c8467a568dc10f66e8c4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

1.4.0 This release

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

1 release file

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page