Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — JWT authentication bypass via algorithm confusion (Apprentice) · 🇬🇧
- PortSwigger — JWT authentication bypass via algorithm confusion with no exposed key (Apprentice) · 🇬🇧
- PortSwigger — JWT authentication bypass via flawed signature verification (Apprentice) · 🇬🇧
- PortSwigger — JWT authentication bypass via unverified signature (Apprentice) · 🇬🇧
- HackTheBox — Secret (Fácil) · 🇪🇸 🇬🇧 📹
- PortSwigger — JWT authentication bypass via jku header injection (Practitioner) · 🇬🇧
Curated resources
HTB machines practicing JSON Web Tokens (JWT) (10)
PortSwigger labs practicing JSON Web Tokens (JWT) (8)
← Back to the full glossary Last updated: 2026-08-13