JWT Token Pentesting
JWT Token Pentesting
1. Check the exp claim for token - Set appropriate token lifetimes based
Tokens have very long expiration Tokens should have
Excessive Token lifetime. on risk assessments.
10 times, increasing the risk window reasonable lifetimes.
Lifetime 2. Assess if the duration is - Use short-lived tokens with refresh
if compromised. Excessively long
appropriate. tokens if necessary.