JSON Web Tokens (JWT)

🔒 Pro Hard Course Online Avg. time 30 min Solved by 0 2 keys · 50 pts Access & Authentication

JWTs are everywhere in modern APIs: a signed token the client carries that says who it is. Their security rests entirely on one step — verifying the signature with the server's secret. When that step is weak or skipped, a token stops proving anything. This exercise explains the structure, the common failures, and the safe way to use them.

Skills covered: APIAuthentication
Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain the three parts of a JWT and what each is for
  • Explain why the payload is readable but the signature is what matters
  • Name the classic JWT failures: no verification and algorithm confusion
  • Explain how to verify a token safely

Before you start

These exercises cover what this one builds on.

In this exercise

  1. What a JWT is for
  2. The payload is not a secret
  3. The classic failures
  4. Using JWTs safely
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points