Intentionally vulnerable test server for the JWT Security Checker n8n workflow. Provides one secure and three vulnerable endpoints — each demonstrating a different JWT misconfiguration.
POST /login
curl -s -X POST https://mech.abek.io/login \
-H "Content-Type: application/json" \
-d '{"username":"test"}' | jq .token
Returns a signed HS256 JWT valid for 1 hour. Use the token value in your n8n Endpoints sheet.
POST /deactivate
curl -s -X POST https://mech.abek.io/deactivate \
-H "Content-Type: application/json" \
-d '{"token":"<your_token>"}'
Adds the token to the revoked list. The /secure endpoint will reject it afterwards.
Add these URLs to your n8n Endpoints sheet and run the workflow. Expected results per test case:
| Endpoint | T1 valid token | T2 no auth | T3 tampered | T4 alg:none | Risk |
|---|---|---|---|---|---|
| /secure SECURE | PASS | PASS | PASS | PASS | MEDIUM |
| /vuln/no-auth VULN | PASS | FAIL | PASS | PASS | HIGH |
| /vuln/no-sig-check VULN | PASS | PASS | FAIL | PASS | HIGH |
| /vuln/alg-none VULN | PASS | PASS | PASS | FAIL | CRITICAL |
Fully hardened endpoint. Whitelists HS256, verifies signature, checks revocation list.
GET https://mech.abek.io/secure
Authorization: Bearer <token>
No authentication check. Returns 200 to any request regardless of token.
GET https://mech.abek.io/vuln/no-auth # No Authorization header needed — returns 200
Decodes the JWT payload without verifying the signature. Accepts any token with a valid base64 payload — including tokens with a tampered role or sub.
GET https://mech.abek.io/vuln/no-sig-check Authorization: Bearer <header>.<tampered_payload>.<any_signature> # Returns 200 — signature never checked
Does not restrict allowed algorithms. Accepts alg:none tokens with no signature.
GET https://mech.abek.io/vuln/alg-none Authorization: Bearer eyJhbGciOiJub25lIn0.eyJzdWIiOiJoYWNrZXIifQ. # Returns 200 — unsigned token accepted