> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# JSON Web Tokens (JWT)

> Cross-platform resources for JSON Web Tokens (JWT): curated HTB machines, PortSwigger labs and TryHackMe rooms with validated writeups and related skills.

# JSON Web Tokens (JWT)

This page aggregates **cross-platform resources to practice JSON Web Tokens (JWT)**: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills.

## Curated resources

| Source      | Link                                                                                 |
| ----------- | ------------------------------------------------------------------------------------ |
| PortSwigger | [https://portswigger.net/web-security/jwt](https://portswigger.net/web-security/jwt) |

## HTB machines practicing JSON Web Tokens (JWT) (10)

| Machine                                                     | OS      | Difficulty                                           |
| ----------------------------------------------------------- | ------- | ---------------------------------------------------- |
| [Backend](/en/htb/machines/linux/medio/backend)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [BackendTwo](/en/htb/machines/linux/medio/backendtwo)       | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Breadcrumbs](/en/htb/machines/windows/dificil/breadcrumbs) | Windows | <span className="dbadge dbadge-hard">HARD</span>     |
| [Epsilon](/en/htb/machines/linux/medio/epsilon)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Noter](/en/htb/machines/linux/medio/noter)                 | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [OverGraph](/en/htb/machines/linux/dificil/overgraph)       | Linux   | <span className="dbadge dbadge-hard">HARD</span>     |
| [Player](/en/htb/machines/linux/dificil/player)             | Linux   | <span className="dbadge dbadge-hard">HARD</span>     |
| [Secret](/en/htb/machines/linux/facil/secret)               | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [TheNotebook](/en/htb/machines/linux/medio/thenotebook)     | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Unicode](/en/htb/machines/linux/medio/unicode)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |

## PortSwigger labs practicing JSON Web Tokens (JWT) (8)

| Lab                                                                                                                                                                                         | Difficulty                                                 | Topic                 | Official                                                                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| [JWT authentication bypass via algorithm confusion](/en/portswigger/labs/jwt/algorithm-confusion-jwt-authentication-bypass-via-algorithm-confusion)                                         | <span className="dbadge dbadge-easy">APPRENTICE</span>     | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/algorithm-confusion/lab-jwt-authentication-bypass-via-algorithm-confusion)                     |
| [JWT authentication bypass via algorithm confusion with no exposed key](/en/portswigger/labs/jwt/algorithm-confusion-jwt-authentication-bypass-via-algorithm-confusion-with-no-exposed-key) | <span className="dbadge dbadge-easy">APPRENTICE</span>     | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/algorithm-confusion/lab-jwt-authentication-bypass-via-algorithm-confusion-with-no-exposed-key) |
| [JWT authentication bypass via flawed signature verification](/en/portswigger/labs/jwt/jwt-authentication-bypass-via-flawed-signature-verification)                                         | <span className="dbadge dbadge-easy">APPRENTICE</span>     | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-flawed-signature-verification)                               |
| [JWT authentication bypass via unverified signature](/en/portswigger/labs/jwt/jwt-authentication-bypass-via-unverified-signature)                                                           | <span className="dbadge dbadge-easy">APPRENTICE</span>     | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-unverified-signature)                                        |
| [JWT authentication bypass via jku header injection](/en/portswigger/labs/jwt/jwt-authentication-bypass-via-jku-header-injection)                                                           | <span className="dbadge dbadge-medium">PRACTITIONER</span> | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-jku-header-injection)                                        |
| [JWT authentication bypass via jwk header injection](/en/portswigger/labs/jwt/jwt-authentication-bypass-via-jwk-header-injection)                                                           | <span className="dbadge dbadge-medium">PRACTITIONER</span> | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-jwk-header-injection)                                        |
| [JWT authentication bypass via kid header path traversal](/en/portswigger/labs/jwt/jwt-authentication-bypass-via-kid-header-path-traversal)                                                 | <span className="dbadge dbadge-medium">PRACTITIONER</span> | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-kid-header-path-traversal)                                   |
| [JWT authentication bypass via weak signing key](/en/portswigger/labs/jwt/jwt-authentication-bypass-via-weak-signing-key)                                                                   | <span className="dbadge dbadge-medium">PRACTITIONER</span> | JWT (JSON Web Tokens) | [Open](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-weak-signing-key)                                            |

***

← [Back to the full glossary](/en/glossary)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"JSON Web Tokens (JWT)","termCode":"jwt-attacks","inLanguage":"en","url":"https://rootea.es/en/skills/jwt-attacks","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Tactical pentesting glossary","url":"https://rootea.es/en/glossary"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"HTB machines practicing JSON Web Tokens (JWT)","numberOfItems":10,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/en/htb/machines/linux/medio/backend","name":"Backend"},{"@type":"ListItem","position":2,"url":"https://rootea.es/en/htb/machines/linux/medio/backendtwo","name":"BackendTwo"},{"@type":"ListItem","position":3,"url":"https://rootea.es/en/htb/machines/windows/dificil/breadcrumbs","name":"Breadcrumbs"},{"@type":"ListItem","position":4,"url":"https://rootea.es/en/htb/machines/linux/medio/epsilon","name":"Epsilon"},{"@type":"ListItem","position":5,"url":"https://rootea.es/en/htb/machines/linux/medio/noter","name":"Noter"},{"@type":"ListItem","position":6,"url":"https://rootea.es/en/htb/machines/linux/dificil/overgraph","name":"OverGraph"},{"@type":"ListItem","position":7,"url":"https://rootea.es/en/htb/machines/linux/dificil/player","name":"Player"},{"@type":"ListItem","position":8,"url":"https://rootea.es/en/htb/machines/linux/facil/secret","name":"Secret"},{"@type":"ListItem","position":9,"url":"https://rootea.es/en/htb/machines/linux/medio/thenotebook","name":"TheNotebook"},{"@type":"ListItem","position":10,"url":"https://rootea.es/en/htb/machines/linux/medio/unicode","name":"Unicode"}]}`}
</script>

*Last updated: 2026-06-07*
