Get in Touch

Course Outline

Introduction

  • JWT structure overview.
  • Common use cases for JWT.

JWT Validation

  • Symmetric token signatures.
  • Asymmetric token signatures.
  • Token validation processes.
  • Claim validation.

Securing Against Stolen JWTs

  • Strategies for handling compromised JWTs.
  • Secure JWT storage methods.
  • JWT invalidation techniques.

Managing Cryptographic Keys

  • Overview of secret keys.
  • Embedding the public key.
  • Incorporating a URL that points to the key.

JWT Security Vulnerabilities

  • Brute force attacks.
  • Algorithm confusion: modifying RS256 to HS256.
  • The 'none' algorithm vulnerability.

Summary and Next Steps

Requirements

  • Fundamental knowledge of web services.

Audience

  • Software Developers.
 7 Hours

Number of participants


Price per participant

Testimonials (5)

Upcoming Courses

Related Categories