# wallarm/jwt-secrets

Repository: https://github.com/wallarm/jwt-secrets
Canonical: https://ross.abutalabs.com/products/jwt-secrets
License: MIT
License Family: permissive
Last push: 2025-03-12T06:46:48+00:00

## Health v2 (maintenance only)
Score: 37/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 11, release rhythm 35, longevity 100
- inputs: {"age_days": 2191, "days_push": 539, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1136, forks 211 (observed 2026-08-28T04:03:43.659569+00:00)

## What it is
A curated wordlist of thousands of publicly leaked JWT signing secrets, collected via Google dorks and GitHub BigQuery scans. It is used for detecting weak JWT secrets through traffic analysis and integrates with the JWT heartbreaker Burp extension.

## Use cases
- brute-force JWT signing secrets during penetration tests
- detect weak JWT secrets in API traffic with a WAF
- test whether my app's JWT secret is guessable
- feed a JWT secret wordlist into Burp Suite
- audit token security for hardcoded secrets

## When to choose
- you need a comprehensive list of known leaked JWT secrets for security testing
- you use Wallarm NGWAF or the JWT heartbreaker Burp extension

## When to avoid
- you need a general-purpose password cracking wordlist
- you want a tool rather than a static dataset

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing, vulnerability-scanning
- domain: security, developer-tools, apis
- platform: cross-platform
- tags: jwt, wordlist, secrets, brute-force, burp-extension

## Member repositories
- wallarm/jwt-secrets (main) score 37

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:43.659569+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:36:32.768038+00:00, confidence not recorded.
  - readme: https://github.com/wallarm/jwt-secrets (fetched 2026-08-28T04:03:43.659569+00:00, sha b1940561455b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
