JWTs: structure, verification, pitfalls

P55.tokens-jwt.01 · Audience: guest, it-ml, language-pro · Prerequisites: HMAC, integrity & timing

Real LLM grading for this pageLLM grading (this page):

A JWT carries claims in a signed header.payload.signature. Trusting one means verifying it properly — and the classic failures (alg:none, key confusion, unchecked exp) are exactly where real systems get broken into. This module builds an HS256 verifier from scratch (HMAC over base64url, ties P52) that rejects each of those attacks.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — verify a JWT (and reject alg:none)

Loading exercise…

My notes on this module

Loading your notes...

JWTs: structure, verification, pitfalls — TransformerLab