$npx skillfedfor your agent

myjwt

Pentesting Tool for JWT(JSON Web Tokens).Modify/Crack/Check Your jwt.

Worth itPyPI WWW/HTTPReleased Jul 202484.9K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — myjwt-2.1.0-py3-none-any.whl
v2.1.0 · released 2024-07-10 · Python >=3.10

Yes. The tool is actively maintained, has no external dependencies, supports current Python versions, carries a permissive license, and has no known vulnerabilities. It is well-suited for security professionals and developers who need to test JWT implementations. Install it if you regularly perform JWT security assessments or CTF challenges.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low install friction with no runtime dependencies.
  • Actively maintained with recent commits and production-stable status; supports current Python versions (3.10, 3.11, 3.12).

License · maintenance · safety

permissive license (permissive) — Permissive license allows use in commercial and private projects with minimal restrictions.

last release 2024-07-10 (765 days) · last repo commit 2026-06-08 · 138 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 84,851 downloads/mo, #13,966 on PyPI

Verify before relying

pip install myjwt
myjwt YOUR_JWT_TOKEN --print
myjwt YOUR_JWT_TOKEN --add-payload "username=admin" --sign mysecretkey
  • Whether the tool's exploitation features (RSA/HMAC confusion, kid injection, jku/x5u bypass) work reliably against real-world JWT implementations.
  • Whether brute-force and regex-crack features scale adequately for large wordlists or complex patterns.
  • Whether the clipboard integration and HTTP request features work consistently across different operating systems.
Same gist for agents: .md · .json

What it is and what it does

MyJWT is a command-line pentesting tool designed for security researchers, CTF players, and developers to inspect, modify, and test JWT tokens. It provides a user interface for decoding JWTs, altering headers and payloads, signing with custom keys, and attempting to crack or verify signatures through brute-force or regex-based attacks. The tool also includes features to test known JWT vulnerabilities such as the none algorithm, RSA/HMAC confusion, kid injection, and jku/x5u header bypasses.

The tool operates as a standalone CLI with no external runtime dependencies, making it lightweight to install and run. It can modify JWT components, send crafted tokens to target URLs with custom HTTP methods and data, and copy results to the clipboard for easy integration into testing workflows. It's particularly useful for security assessments where JWT validation logic needs to be tested or where token manipulation is part of the attack surface.

Use it for

  • Test for the none algorithm vulnerability in JWT implementations by attempting to bypass signature verification.
  • Brute-force JWT secrets using a wordlist to discover weak signing keys used in production systems.
  • Modify JWT payloads and headers to test authorization bypass or privilege escalation in web applications.
  • Exploit RSA/HMAC algorithm confusion to forge valid signatures using a public key as the HMAC secret.
  • Test jku and x5u header injection vulnerabilities to bypass JWT validation through external key sources.
  • Crack JWT signatures using regex patterns to guess keys based on known character sets or patterns.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The tool is actively maintained, has no external dependencies, supports current Python versions, carries a permissive license, and has no known vulnerabilities. It is well-suited for security professionals and developers who need to test JWT implementations. Install it if you regularly perform JWT security assessments or CTF challenges.

Install

myjwt on PyPI

Before you install

Low install friction with no runtime dependencies. Actively maintained with recent commits and production-stable status; supports current Python versions (3.10, 3.11, 3.12).

Requires Python 3.10 or later.

License in practice

Permissive license allows use in commercial and private projects with minimal restrictions.

Quickstart

pip install myjwt
myjwt YOUR_JWT_TOKEN --print
myjwt YOUR_JWT_TOKEN --add-payload "username=admin" --sign mysecretkey

Verify before relying

  • Whether the tool's exploitation features (RSA/HMAC confusion, kid injection, jku/x5u bypass) work reliably against real-world JWT implementations.
  • Whether brute-force and regex-crack features scale adequately for large wordlists or complex patterns.
  • Whether the clipboard integration and HTTP request features work consistently across different operating systems.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 765 days since the last release
Last repo commit
First released
Downloads84,851 / month, #13,966 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Topic :: Internet :: WWW/HTTPTopic :: Security

Evidence: myjwt-2.1.0-py3-none-any.whl

Tags

Capabilities
jwt pentesting tooljwt manipulation clijwt vulnerability testingjwt cracking brute forcejwt signature bypassjwt header injectionjwt algorithm confusion
Topics
jwt-testingpenetration-testingcryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “jwt pentesting tool”

  • myjwtA command-line tool for testing and manipulating JSON Web Tokens…
  • minikerberosA pure-Python Kerberos client library supporting password,…
  • asysocksAsynchronous SOCKS5, SOCKS4, and HTTP proxy client and server library…

Give your agent the search over MCP, or paste the wish link into any chat.

More WWW/HTTP packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
h11 With conditions
PyPI · WWW/HTTP · released Apr 2025

h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.

MITpure Python · 3.8+aging
894.9Mdownloads / mo
httpx Worth it
PyPI · WWW/HTTP · released Dec 2024

HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.

Install it if you are building new projects or modernizing existing ones that rely on HTTP.

BSD-3-Clausepure Python · 3.8+
797.0Mdownloads / mo
httpcore With conditions
PyPI · WWW/HTTP · released Apr 2025

A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.

BSD-3-Clausepure Python · 3.8+aging
783.6Mdownloads / mo
aiohttp Worth it
PyPI · WWW/HTTP · released Jul 2026

aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.

Install it if you need async HTTP client or server capabilities in asyncio-based applications.

permissive licensecompiled wheel · 3.10+
643.6Mdownloads / mo

See also python-jwt · jose · jwskate · jwt · python-jose · types-jwt · joserfc · okta-jwt-verifier · django-ninja-jwt · PyJWT