JSON Web Tokens (JWT)
JWTs are everywhere in modern APIs: a signed token the client carries that says who it is. Their security rests entirely on one step — verifying the signature with the server's secret. When that step is weak or skipped, a token stops proving anything. This exercise explains the structure, the common failures, and the safe way to use them.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain the three parts of a JWT and what each is for
- Explain why the payload is readable but the signature is what matters
- Name the classic JWT failures: no verification and algorithm confusion
- Explain how to verify a token safely
Before you start
These exercises cover what this one builds on.
- Session Management Medium
- How Passwords Are Stored and Cracked Medium
In this exercise
- What a JWT is for
- The payload is not a secret
- The classic failures
- Using JWTs safely
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points