Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
6 to work through
-
intermediate
Your JWTs last one hour. An employee is dismissed. Security asks why they still had system access for 45 minutes. Explain and fix.
2 min answer -
advanced
A platform uses signed tokens for service-to-service and client authentication. Which properties must be verified on every use, and what goes wrong when they are not?
2 min answer -
advanced
A team is designing token-based authentication for a distributed system. What are the significant design decisions, and which common JWT choices cause problems later?
2 min answer -
advanced
After a routine signing key rotation, roughly 3% of API requests start failing with 401s. The rate decays over about ten minutes and returns on the next rotation. Tokens look valid and clocks are synchronised. What is happening?
3 min answer -
advanced
An identity provider issues tokens that applications validate locally without a network call. What does that buy, and what is the necessary consequence for revocation?
2 min answer -
advanced
Your JWT-based auth means a fired employee keeps access for 15 minutes after their account is disabled. Security says that is unacceptable. What are the options?
2 min answer
5 terms in this topic
JWKS
A published endpoint listing an issuer's current public keys, allowing resource servers to validate token signatures without a shared secret and to s…
conceptRefresh Token
A long-lived credential used solely to obtain new short-lived access tokens, so sessions can persist without long-lived access tokens circulating.
conceptRevocation Window
The period during which a revoked credential remains accepted, which for locally-validated tokens is exactly the token lifetime - the unavoidable pri…
practiceToken Audience Validation
Verifying that a signed token was issued for the service consuming it, without which a legitimately obtained low-privilege token is replayable agains…
conceptToken Revocation Gap
The window between deciding a token should no longer be valid and it actually ceasing to work, which for self-contained tokens is its remaining lifetime.
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.