Decoder
Encode, decode, hash, forge and inspect JWTs, peel layered encodings, and generate WAF-bypass polyglots — without leaving Hugin.
Decoder is the workbench for mangling data. It has five tabs: Transform (the operation chain), Analyze, JWT, Polyglot, and Smart Decode. Drop a file onto the input to load it as text. Every operation is saved to a session history you can filter and reload — an in-memory ring that drops the oldest entries as it fills.

Decoder is part of the free Community tier. Everything on this page works without a Pro license.
Transform
Stack operations and feed each into the next. A chain reports every step's input and output, so you can see exactly where a transform breaks — decode a value, change one byte mid-chain, and re-encode it through the same layers.
- Encode and decode: Base64, Base64URL (plus a strict decoder that refuses the
standard-alphabet fallback, for JWT signature segments), Base32, ASCII85, URL,
hex (plus
0x-prefixed and uppercase), HTML, Unicode escapes, octal, binary, gzip, deflate, ROT13, ROT47, Atbash, Morse, gopher, Quoted-Printable, and Punycode. - Hash: SHA-256/512, SHA3-256/512, BLAKE2b/2s, RIPEMD-160, CRC32, and keyed HMAC-SHA256/512 — plus MD5 and SHA-1, flagged as legacy and fingerprint-only.
- Transform and clean up: upper/lower case, reverse, trim, length, strip whitespace, strip newlines, strip control bytes (NUL/CR/LF), JSON prettify, JSON minify, and XML prettify.
Encoders that slip filters
Most filters check the bytes they expect to see. These encoders change the bytes without changing what the application finally decodes, so the payload reaches the sink intact.
%2522 and deeper. Beats a filter that decodes the value once before it inspects
it, then hands it to an app that decodes again.
Percent-encodes every byte, including the ones a normal encoder leaves alone, to push a literal payload past a naive denylist.
Encodes / and . as multi-byte overlong sequences to walk past path-traversal
filters that only match the ASCII bytes.
< and < for <. The browser renders it; a filter grepping for
<script does not see it.
+ADw-script+AD4- style. Lands XSS on a page that sets charset=utf-7.
The encoding browsers use for internationalised domain names — useful against hostname allow/deny checks in open-redirect and SSRF tests.
=XX MIME encoding for email-header injection and other MIME-parsed sinks.
The polyglot engine
The Polyglot tab is a payload arsenal and a payload mutator. Use it three ways.
The Payloads pane holds 622 payloads across 52 contexts — xss_html,
sqli_mysql, ssti_jinja2, ssrf_cloud, xxe, log4j, path_traversal,
jwt, llm_injection, and more. Pick a context, filter by severity or by CWE and
text, then copy a payload and drop it into Repeater or an
Intruder list. Each payload is tagged with its severity,
CWE, and OWASP category.
Paste a payload into the input, open the WAF Bypass pane, choose a class (XSS,
SQLi, LFI, or all), and Generate. You get the same payload re-encoded several
ways — UTF-7, double URL, HTML decimal entities, Unicode escapes, 0x hex,
UTF-8 overlong, and mixed case — each labelled with the filter it is built to
slip. Click a variant to load it back into the input and stack more transforms on
top.
Seven profiles ship for re-encoding a payload past a specific web application
firewall (WAF): Cloudflare, Akamai, AWS, ModSecurity, Imperva, F5 BIG-IP, and
Barracuda. Each rewrites the payload the way that vendor's filter misses —
Cloudflare, for example, randomises the case of <script> and turns alert and
eval into alert and eval. Pass a WAF name to the polyglot
generator to re-encode a whole context set at once; drive it from an AI agent over
MCP or call it from the REST API.
JWT
Decode a token to read its header and payload. Decoder flags alg:none, an
unrecognised algorithm, and an empty signature, so a tampered token is obvious at
a glance.
Then attack it. The header attack helpers rewrite one claim at a time, so you can stage the classic key-confusion probes without hand-editing JSON:
Points kid at ../../../../dev/null (or any path) to test a header-driven key
lookup.
Points jku or x5u at a URL you control, to see if the verifier fetches its
signing key or certificate from you.
Drops an attacker key straight into the header, for libraries that trust
header.jwk over their configured key store.
Forge a token two ways: sign it with HS256 from a secret, or emit an
alg:none unsigned token (a two-step confirm, since Decoder refuses
alg:none by default).
Forge signs HS256 only. HS384 and HS512 are accepted as a header alg value
but currently produce an empty signature — sign with HS256, or use alg:none
deliberately. For any other algorithm, decode and tamper, then test the token in
Repeater.
Secrets come from a picker fed by environment variables
(HUGIN_DECODER_HMAC_KEY, HUGIN_DECODER_JWT_SECRET), the OS keyring, or keys
you register at runtime. Hugin holds them wrapped, wipes them from memory after
use, and never writes them to logs. An empty key is refused; a short key raises a
weak-key warning. The same picker feeds keyed HMAC hashing in the Transform tab.
Analyze and Smart Decode
Analyze guesses the encoding of a blob with a confidence score and an entropy read, so a high-entropy value reads as likely-encrypted rather than encoded. Smart Decode goes further: it detects layered encodings (hex, Base64 / Base64url, URL and double-URL, HTML entities, Unicode escapes, gzip, JWT) and peels them recursively until it reaches plaintext.
Most of exploitation is getting the encoding right. Decode a value to read it, change one thing, and re-encode it with the same layers, then paste it straight into Repeater or an Intruder list.