HMAC Key Confusion

  1. Add the public key (either in pem format or json) to JWT Editor Keys, then in Repeater change the auth type to HS256, change the payload. Finally use Attack->HMAC Key confusion (no need remove trailing space) and resend.