docs

Decoder

Encode, decode, hash, forge and inspect JWTs, peel layered encodings, and generate WAF-bypass polyglots — without leaving Hugin.

Decoder is the workbench for mangling data. It has five tabs: Transform (the operation chain), Analyze, JWT, Polyglot, and Smart Decode. Drop a file onto the input to load it as text. Every operation is saved to a session history you can filter and reload — an in-memory ring that drops the oldest entries as it fills.

The Decoder view with a stacked transform chain
Stack encode, decode, hash, and transform steps and feed each into the next — every step shows its input and output.

Decoder is part of the free Community tier. Everything on this page works without a Pro license.

Transform

Stack operations and feed each into the next. A chain reports every step's input and output, so you can see exactly where a transform breaks — decode a value, change one byte mid-chain, and re-encode it through the same layers.

  • Encode and decode: Base64, Base64URL (plus a strict decoder that refuses the standard-alphabet fallback, for JWT signature segments), Base32, ASCII85, URL, hex (plus 0x-prefixed and uppercase), HTML, Unicode escapes, octal, binary, gzip, deflate, ROT13, ROT47, Atbash, Morse, gopher, Quoted-Printable, and Punycode.
  • Hash: SHA-256/512, SHA3-256/512, BLAKE2b/2s, RIPEMD-160, CRC32, and keyed HMAC-SHA256/512 — plus MD5 and SHA-1, flagged as legacy and fingerprint-only.
  • Transform and clean up: upper/lower case, reverse, trim, length, strip whitespace, strip newlines, strip control bytes (NUL/CR/LF), JSON prettify, JSON minify, and XML prettify.

Encoders that slip filters

Most filters check the bytes they expect to see. These encoders change the bytes without changing what the application finally decodes, so the payload reaches the sink intact.

Double and triple URL-encode

%2522 and deeper. Beats a filter that decodes the value once before it inspects it, then hands it to an app that decodes again.

URL-encode all

Percent-encodes every byte, including the ones a normal encoder leaves alone, to push a literal payload past a naive denylist.

UTF-8 overlong

Encodes / and . as multi-byte overlong sequences to walk past path-traversal filters that only match the ASCII bytes.

HTML decimal and hex entities

&#60; and &#x3c; for <. The browser renders it; a filter grepping for <script does not see it.

UTF-7

+ADw-script+AD4- style. Lands XSS on a page that sets charset=utf-7.

Punycode

The encoding browsers use for internationalised domain names — useful against hostname allow/deny checks in open-redirect and SSRF tests.

Quoted-Printable

=XX MIME encoding for email-header injection and other MIME-parsed sinks.

The polyglot engine

The Polyglot tab is a payload arsenal and a payload mutator. Use it three ways.

Pick a bug class and get a ready payload

The Payloads pane holds 622 payloads across 52 contexts — xss_html, sqli_mysql, ssti_jinja2, ssrf_cloud, xxe, log4j, path_traversal, jwt, llm_injection, and more. Pick a context, filter by severity or by CWE and text, then copy a payload and drop it into Repeater or an Intruder list. Each payload is tagged with its severity, CWE, and OWASP category.

Mutate your own payload into variants

Paste a payload into the input, open the WAF Bypass pane, choose a class (XSS, SQLi, LFI, or all), and Generate. You get the same payload re-encoded several ways — UTF-7, double URL, HTML decimal entities, Unicode escapes, 0x hex, UTF-8 overlong, and mixed case — each labelled with the filter it is built to slip. Click a variant to load it back into the input and stack more transforms on top.

Re-encode for a specific WAF

Seven profiles ship for re-encoding a payload past a specific web application firewall (WAF): Cloudflare, Akamai, AWS, ModSecurity, Imperva, F5 BIG-IP, and Barracuda. Each rewrites the payload the way that vendor's filter misses — Cloudflare, for example, randomises the case of <script> and turns alert and eval into alert and eval. Pass a WAF name to the polyglot generator to re-encode a whole context set at once; drive it from an AI agent over MCP or call it from the REST API.

JWT

Decode a token to read its header and payload. Decoder flags alg:none, an unrecognised algorithm, and an empty signature, so a tampered token is obvious at a glance.

Then attack it. The header attack helpers rewrite one claim at a time, so you can stage the classic key-confusion probes without hand-editing JSON:

kid path traversal

Points kid at ../../../../dev/null (or any path) to test a header-driven key lookup.

jku or x5u to your server

Points jku or x5u at a URL you control, to see if the verifier fetches its signing key or certificate from you.

embedded jwk

Drops an attacker key straight into the header, for libraries that trust header.jwk over their configured key store.

Forge a token two ways: sign it with HS256 from a secret, or emit an alg:none unsigned token (a two-step confirm, since Decoder refuses alg:none by default).

Forge signs HS256 only. HS384 and HS512 are accepted as a header alg value but currently produce an empty signature — sign with HS256, or use alg:none deliberately. For any other algorithm, decode and tamper, then test the token in Repeater.

Secrets come from a picker fed by environment variables (HUGIN_DECODER_HMAC_KEY, HUGIN_DECODER_JWT_SECRET), the OS keyring, or keys you register at runtime. Hugin holds them wrapped, wipes them from memory after use, and never writes them to logs. An empty key is refused; a short key raises a weak-key warning. The same picker feeds keyed HMAC hashing in the Transform tab.

Analyze and Smart Decode

Analyze guesses the encoding of a blob with a confidence score and an entropy read, so a high-entropy value reads as likely-encrypted rather than encoded. Smart Decode goes further: it detects layered encodings (hex, Base64 / Base64url, URL and double-URL, HTML entities, Unicode escapes, gzip, JWT) and peels them recursively until it reaches plaintext.

Most of exploitation is getting the encoding right. Decode a value to read it, change one thing, and re-encode it with the same layers, then paste it straight into Repeater or an Intruder list.

Last updated 2026-06-17.