Quantcast
Viewing all articles
Browse latest Browse all 151

JWT.io Debugger does validate at all. Considers ANY secret as valid. How is this possible?

  1. Go to JWT.io right now and under Verify Signature which contains “your-256-bit-secret” go ahead and type anything in. I mean ANYTHING. What do you see?

Signature Verified.

  1. Go to JWT.io again, then copy & paste your perfectly fine custom JWT in the Encoded Box. Now enter your custom Secret. What do you see?

Signature Verified.

  1. Now go ahead modify your custom Secret under Verify Signature. Yep, go ahead and smash buttons on your keyboard. Type anything. Yes, really. What do you see?

Signature Verified.

How is this possible?

4 posts - 3 participants

Read full topic


Viewing all articles
Browse latest Browse all 151

Trending Articles