Skip to content

Token Analysis ​

The Token Sequencer page (Token Analysis) takes pasted token samples and summarizes uniqueness, length, recognizable formats, and character distribution.

Submitting a Sample ​

  1. Open Utilities > Token Sequencer.
  2. Paste multiple tokens into the input area, one per line. Include enough independently generated samples to inspect variation, not repeated copies of the same token.
  3. Click Analyze.

Collect samples by repeating the operation that generates the token (log in repeatedly, request new CSRF tokens, generate API keys from the UI) and capturing the values from responses.

Analysis Output ​

Entropy score ​

The page computes Shannon entropy from character frequencies within each token and reports average, minimum, maximum, and per-token values. This is not the total cryptographic strength of a token or its generator. Do not compare the displayed score with 64-bit or 128-bit key-strength requirements.

Pattern detection ​

The format detector recognizes JWT-shaped values, UUIDs, common hexadecimal lengths, Base64url-shaped strings, and numeric values. Recognition describes the shape; it does not verify a JWT signature or identify the algorithm that generated a hex token. The separate Request Sequencer also checks simple arithmetic sequences in collected samples.

Character distribution ​

A character-frequency heatmap shows the distribution of printable ASCII characters across the sample. Uneven distribution can reveal structure, but an even distribution does not prove unpredictability.

Interpreting Results ​

Review the displayed measurements alongside the application's token lifecycle, encoding, and generation method. Examples of things to investigate manually:

  • A sequential pattern means an attacker who holds one valid token can enumerate adjacent tokens.
  • A timestamp prefix means the token search space collapses to a narrow time window.
  • Low character diversity means the effective key space is much smaller than the token length suggests.

Use Cases ​

  • Session tokens - investigate duplicate values and unexpectedly small character sets.
  • CSRF tokens - compare independent samples before testing their validation separately.
  • API keys - inspect format and variation; verify generation strength separately.
  • Password reset tokens - a predictable reset token allows account takeover without interaction from the victim.
  • Invite codes and numeric IDs - test whether short codes or auto-increment IDs are exposed in a security-relevant context.

Proprietary software. All rights reserved.