Security · Multiple choice

A service receives a JWT whose header says "alg": "none". What should it do?

hard

Options

Why

Libraries that trusted the header have accepted unsigned tokens (none) and tokens signed with HMAC using the public RSA key as the secret. Pin the algorithm and key, then check exp, the issuer (iss) and the audience (aud), so a token minted for another service is refused.

Review this in your daily deck All cards in Security