Algorithm confusion

A JWT attack where the server trusts the token's header to choose how to verify the signature, including the insecure "none" algorithm.

Learn it hands-on