← back to the grid
cryptohard

JWT Weak Secret

HEMLEM Auth issues HS256 JWT tokens. The engineer who picked the signing secret had a favorite password. The in-page tools let you decode, crack, forge, and submit — no external tools needed.

sandbox · allow-scripts · no-same-origin · null-origin● live

practice grid — every target is a toy in your own browser. this is not an invitation to test the real site.

enter flag