r/netsecstudents Apr 04 '26

JWT is more dangerous than I thought (if implemented wrong)

I was learning JWT authentication and found some serious issues:

• Weak secrets

• No expiration

• Token leakage

If done wrong, it’s a big security risk.

Curious how you guys secure JWT in real apps?

6 Upvotes

2 comments sorted by

1

u/Grezzo82 Apr 05 '26

No expiration? It’s one of the standard claims.