JWT Attacks
data = base64urlEncode(header) + '.' + base64urlEncode(payload)
hashedData = hash(data, secret)
signature = base64urlEncode(hashedData)
jwt = data + '.' + signatureChanging the algorithm to “none”
Changing the algorithm from RS256 to HS256
Brute forcing the key
Timing attack
Last updated