JWT Security Checker — Test Server

Intentionally vulnerable test server for the JWT Security Checker n8n workflow. Provides one secure and three vulnerable endpoints — each demonstrating a different JWT misconfiguration.


1. Create a Token

POST /login

curl -s -X POST https://mech.abek.io/login \
  -H "Content-Type: application/json" \
  -d '{"username":"test"}' | jq .token

Returns a signed HS256 JWT valid for 1 hour. Use the token value in your n8n Endpoints sheet.

2. Deactivate a Token

POST /deactivate

curl -s -X POST https://mech.abek.io/deactivate \
  -H "Content-Type: application/json" \
  -d '{"token":"<your_token>"}'

Adds the token to the revoked list. The /secure endpoint will reject it afterwards.


3. Test Endpoints

Add these URLs to your n8n Endpoints sheet and run the workflow. Expected results per test case:

Endpoint T1 valid token T2 no auth T3 tampered T4 alg:none Risk
/secure SECURE PASS PASS PASS PASS MEDIUM
/vuln/no-auth VULN PASS FAIL PASS PASS HIGH
/vuln/no-sig-check VULN PASS PASS FAIL PASS HIGH
/vuln/alg-none VULN PASS PASS PASS FAIL CRITICAL

/secure SECURE

Fully hardened endpoint. Whitelists HS256, verifies signature, checks revocation list.

GET https://mech.abek.io/secure
Authorization: Bearer <token>

/vuln/no-auth VULNERABLE — T2

No authentication check. Returns 200 to any request regardless of token.

GET https://mech.abek.io/vuln/no-auth
# No Authorization header needed — returns 200

/vuln/no-sig-check VULNERABLE — T3

Decodes the JWT payload without verifying the signature. Accepts any token with a valid base64 payload — including tokens with a tampered role or sub.

GET https://mech.abek.io/vuln/no-sig-check
Authorization: Bearer <header>.<tampered_payload>.<any_signature>
# Returns 200 — signature never checked

/vuln/alg-none VULNERABLE — T4

Does not restrict allowed algorithms. Accepts alg:none tokens with no signature.

GET https://mech.abek.io/vuln/alg-none
Authorization: Bearer eyJhbGciOiJub25lIn0.eyJzdWIiOiJoYWNrZXIifQ.
# Returns 200 — unsigned token accepted