JWT None Algorithm
Challenge Question
This verification service trusts a signed token to say who you are, and it takes the token's own claim about which signing algorithm was used at face value. Not every algorithm actually requires a signature to be trusted. Forge a token that verifies as someone you're not.Submit Flag
Details
- CategoryWeb Exploitation
- Authoradmin
- AddedJul 4, 2026
- Avg. Time to Solve—
Recent Solvers
No one has solved this yet. Be the first!