⚠️Requests 1 sensitive permission
Description
Stealthy JWT security testing toolkit - Auto-detect, decode, analyze & test JWT vulnerabilities for authorized pentesting & bug bounty.
Detailed Description
TokenNinja - Professional JWT Security Testing Toolkit
A powerful DevTools extension for security researchers, penetration testers, and bug bounty hunters to identify and test JWT (JSON Web Token)
vulnerabilities.
KEY FEATURES:
Auto-Detection
• Automatically scans pages for JWTs in cookies, localStorage, sessionStorage, headers, and URLs
• Intercepts Authorization headers from XHR/Fetch requests
• Supports Next.js, Nuxt.js, Redux, and other modern frameworks
Token Analysis
• Decode JWT header, payload, and signature
• Identify security issues (weak algorithms, missing expiration, exposed secrets)
• Visual security risk indicators
Attack Generation (80+ Attack Vectors)
• Algorithm None - Test for unsigned token acceptance
• Algorithm Confusion - RS256 to HS256 key confusion attacks
• Signature Stripping - Empty and malformed signature tests
• Expiry Manipulation - Extend token lifetime, remove expiration
• Key ID (kid) Injection - Path traversal, SQL injection, command injection
• JKU/X5U Injection - Remote key URL manipulation
• Privilege Escalation - Role, admin, and permission tampering
• Issuer/Audience Bypass - iss and aud claim manipulation
• Type Confusion - JWT header type attacks
One-Click Testing
• Test modified tokens against target endpoints
• Instant vulnerability detection feedback
• Copy attack payloads to clipboard
IMPORTANT: This tool is designed for AUTHORIZED security testing only. Use responsibly on systems you have permission to test. Ideal for:
• Penetration testing engagements
• Bug bounty programs
• Security research
• CTF competitions
• Educational purposes
Access via browser popup or DevTools panel for an enhanced testing experience.
Version 1.0.0
Category
Developer Tools
Tags/Keywords
JWT, JSON Web Token, security, penetration testing, bug bounty, vulnerability scanner, token decoder, authentication, cybersecurity, devtools
Reviews
Loading reviews...
Permissions (4)
Permissions
activeTabℹ Can access the current tab when you click the extension cookiesℹ Can read and modify browser cookies scriptingℹ Can inject scripts into web pages storageℹ Can store data locally in your browser
Details
| Version | 1.0.1 |
| Updated | Dec 10, 2025 |
| Size | 34.93KiB |
| First Seen | Mar 27, 2026 |
Popular in developer
TouchEn PC보안 확장
by 라온시큐어
8M
★ 1.33
developer
8M
★ 1.33
developer
React Developer Tools
by Meta
5M
★ 3.95
developer
5M
★ 3.95
developer
Lighthouse
by lighthouse-extension-owners
1M
★ 4.42
developer
1M
★ 4.42
developer
Контур.Плагин
by kontur.extension
1M
★ 3.11
developer
1M
★ 3.11
developer
Similarweb - Website Traffic & SEO Checker
by Similarweb
1M
★ 4.66
developer
1M
★ 4.66
developer
Popular Extensions
Adobe Acrobat: PDF edit, convert, sign tools
by Adobe Inc.
331M
★ 4.40
workflow
331M
★ 4.40
workflow
Grammarly: AI Writing Assistant and Grammar Checker App
by Grammarly
42M
★ 4.50
communication
42M
★ 4.50
communication
Chrome Remote Desktop
by Chrome Remote Desktop Release Managers
38M
★ 3.14
workflow
38M
★ 3.14
workflow
Microsoft Single Sign On
by Microsoft
36M
★ 2.27
workflow
36M
★ 2.27
workflow
Cisco Webex Extension
by cisco.chromestore
23M
★ 2.34
social
23M
★ 2.34
social