vamp-jwt-audit
PulseGate's liveness check found it on 19 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 19 Sep 2026. How this is checked
vamp-jwt-audit is an open-source command-line JWT security auditor. It checks for issues including alg=none acceptance, RS256-to-HS256 algorithm confusion, and weak HMAC secrets, for security professionals and developers testing authentication systems.
Inferred · not functionally tested
Overview
5 featuresPurpose: Finding common JWT implementation vulnerabilities during security audits and penetration tests.
Inferred · not functionally tested
Audience: security researchers and penetration testers
Inferred · not functionally tested
Functions: Unknown
Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
In the Penetration testing & red teaming space, vamp-jwt-audit takes a focused approach. Inferred · not functionally tested: It focuses on finding common JWT implementation vulnerabilities during security audits and penetration tests. Inferred · not functionally tested: vamp-jwt-audit is an open-source project aimed at security researchers and penetration testers. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: It runs on the command line, and it can be self-hosted.
Vampsecure Labs builds and maintains vamp-jwt-audit, and it first shipped in 2026. Development happens publicly on GitHub with 11 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include JWT auditing, algorithm confusion checks, and alg=none testing.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- JWT auditing
- Algorithm confusion checks
- alg=none testing
- HMAC brute force
- Authentication testing
Topics: Inferred · not functionally tested
Built with & integrations
Trust & compliance
Indexing history
6What PulseGate has recorded for this listing
- Indexed19 Sep · 01:35 UTCvamp-jwt-audit seen via PyPI Bulk EnumeratorSource: PyPI Bulk Enumerator · Open
Frequently asked questions about vamp-jwt-audit
- What is vamp-jwt-audit?
- Inferred · not functionally tested: Vamp-jwt-audit focuses on finding common JWT implementation vulnerabilities during security audits and penetration tests. It is catalogued under Penetration testing & red teaming on PulseGate.
- Who should use vamp-jwt-audit?
- Inferred · not functionally tested: vamp-jwt-audit is an open-source project built for security researchers and penetration testers.
- Is vamp-jwt-audit free?
- Basis unknown · not verified: Yes — vamp-jwt-audit is open source under the MIT license and free to use.
- What platforms does vamp-jwt-audit run on?
- Basis unknown · not verified: vamp-jwt-audit runs on the command line. It can also be self-hosted.
- Is vamp-jwt-audit still active?
- PulseGate's liveness check found it on 19 Sep 2026. Its GitHub repository shows 11 commits in the last 90 days.
- What projects are similar to vamp-jwt-audit?
- Similar projects tracked by PulseGate include vamp-oauth-audit, vamp-ssl-audit, and vamp-windows-audit.vamp-oauth-auditvamp-ssl-auditvamp-windows-audit
- Who makes vamp-jwt-audit?
- vamp-jwt-audit is developed by Vampsecure Labs.
- How long has vamp-jwt-audit been around?
- vamp-jwt-audit first shipped in 2026.
Similar projects
Closest matches by what these projects do