JWTs: structure, verification, pitfalls
P55.tokens-jwt.01 · Audience: guest, it-ml, language-pro · Prerequisites: HMAC, integrity & timing
A JWT carries claims in a signed header.payload.signature. Trusting one means verifying it
properly — and the classic failures (alg:none, key confusion, unchecked exp) are exactly
where real systems get broken into. This module builds an HS256 verifier from scratch (HMAC over
base64url, ties P52) that rejects each of those attacks.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — verify a JWT (and reject alg:none)
Loading exercise…
My notes on this module
Loading your notes...