Why Decoding a JWT Is Not Verifying It (And How Security Bugs Slip Through)
Decoding a JWT only unmasks Base64URL strings. Here is how alg: none bypasses, algorithm confusion, and unverified claims slip into production.
Oct 7, 20266 min read

Search for a command to run...
Articles tagged with #security
Decoding a JWT only unmasks Base64URL strings. Here is how alg: none bypasses, algorithm confusion, and unverified claims slip into production.

Last Tuesday, a staging auth bug had three devs stumped for half an afternoon. Nginx was spitting 401 Unauthorized. But the tester dumped their Bearer token into Chrome's DevTools console, ran JSON.pa
