What are JWTs
Building a Secure Signed JWT
- Definitions
- Out of scope
- Security considerations
- Creating tokens
- Holding tokens
- Consuming a JWT
- In conclusion
Pros and Cons of JWTs
- JWTs expire at specific intervals
- JWTs are signed
- JWTs aren’t easily revocable
- JWTs have exploits
- Sessions as an alternative
Revoking JWTs & JWT Expiration
- Reduce the duration of the JWT
- Rotate keys
- Build a deny list
- Conclusion
Anatomy of a JWT
- The header
- The body
- Signature
- Limits
- Conclusion