---
url: https://docs.ogmabox.com/app/utilities/token-analysis.md
description: Analyze token samples for structure and predictability in Ogma.
---

# Token Analysis

The **Token Sequencer** page (Token Analysis) takes pasted token samples and summarizes uniqueness, length, recognizable formats, and character distribution.

## Submitting a Sample

1. Open **Utilities > Token Sequencer**.
2. Paste multiple tokens into the input area, one per line. Include enough independently generated samples to inspect variation, not repeated copies of the same token.
3. Click **Analyze**.

Collect samples by repeating the operation that generates the token (log in repeatedly, request new CSRF tokens, generate API keys from the UI) and capturing the values from responses.

## Analysis Output

### Entropy score

The page computes Shannon entropy from character frequencies within each token and reports average, minimum, maximum, and per-token values. This is not the total cryptographic strength of a token or its generator. Do not compare the displayed score with 64-bit or 128-bit key-strength requirements.

### Pattern detection

The format detector recognizes JWT-shaped values, UUIDs, common hexadecimal lengths, Base64url-shaped strings, and numeric values. Recognition describes the shape; it does not verify a JWT signature or identify the algorithm that generated a hex token. The separate [Request Sequencer](./request-sequencer.md) also checks simple arithmetic sequences in collected samples.

### Character distribution

A character-frequency heatmap shows the distribution of printable ASCII characters across the sample. Uneven distribution can reveal structure, but an even distribution does not prove unpredictability.

## Interpreting Results

Review the displayed measurements alongside the application's token lifecycle, encoding, and generation method. Examples of things to investigate manually:

* A sequential pattern means an attacker who holds one valid token can enumerate adjacent tokens.
* A timestamp prefix means the token search space collapses to a narrow time window.
* Low character diversity means the effective key space is much smaller than the token length suggests.

## Use Cases

* **Session tokens** - investigate duplicate values and unexpectedly small character sets.
* **CSRF tokens** - compare independent samples before testing their validation separately.
* **API keys** - inspect format and variation; verify generation strength separately.
* **Password reset tokens** - a predictable reset token allows account takeover without interaction from the victim.
* **Invite codes and numeric IDs** - test whether short codes or auto-increment IDs are exposed in a security-relevant context.

## Related Pages

* [JWT](./jwt.md)
* [Request Sequencer](./request-sequencer.md)
* [Compare](./compare.md)
