Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.1 KiB

API Reference: Testing JWT Token Security

PyJWT Library

Installation

pip install PyJWT

Encoding (Creating Tokens)

import jwt
token = jwt.encode(payload, secret, algorithm="HS256")

Decoding

# Without verification (for analysis)
payload = jwt.decode(token, options={"verify_signature": False})

# With verification
payload = jwt.decode(token, secret, algorithms=["HS256"])

Supported Algorithms

Algorithm Type Description
HS256 HMAC SHA-256 symmetric signing
HS384 HMAC SHA-384 symmetric signing
HS512 HMAC SHA-512 symmetric signing
RS256 RSA SHA-256 asymmetric signing
RS384 RSA SHA-384 asymmetric signing
ES256 ECDSA P-256 curve signing

JWT Attack Types

Attack Description Severity
Algorithm None Set alg to "none", remove signature Critical
Algorithm Confusion Switch RS256 to HS256, sign with public key Critical
HMAC Brute Force Crack weak signing secrets Critical
JKU Injection Point JWK Set URL to attacker server Critical
KID Injection SQL injection or path traversal in Key ID Critical
Claim Tampering Modify role/sub claims after key compromise High
Expired Token Reuse Use tokens past expiration High
No Revocation Tokens valid after logout/password change High

JWT Structure

Header.Payload.Signature
base64url({"alg":"HS256","typ":"JWT"}).base64url({"sub":"1","role":"user"}).HMACSHA256(...)

Standard Claims

Claim Description
iss Token issuer
sub Subject (user identifier)
aud Intended audience
exp Expiration time (Unix timestamp)
nbf Not valid before time
iat Issued at time
jti Unique token identifier

References