Authentication & Authorization Medium technical 1 views 1 min read

What are the most common JWT security pitfalls?

Peer-reviewed by HireXTech Technical Panel Updated for 2025/2026 hiring Editorial standards
Practise this track
Interviewer Expectations for this Question
01
Core Competency

Assesses fundamental understanding of Authentication & Authorization conventions, runtime behavior, and memory/performance considerations.

02
Evaluation Criteria

Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.

Comprehensive Model Answer Verified Solution
  • Accepting the none algorithm or trusting the token header for algorithm selection, which enables algorithm confusion attacks. Pin the expected algorithm server-side.
  • Not verifying the signature at all, or using a weak shared secret that can be brute-forced.
  • Storing JWTs in localStorage, where any XSS can exfiltrate them. Prefer HttpOnly, Secure cookies for browsers.
  • Long expiry with no revocation strategy; a stolen token is valid until it expires. Use short lifetimes and refresh tokens.
  • Putting sensitive data in the payload and forgetting it is only base64url encoded, readable by anyone.
  • Skipping validation of exp, nbf, iss or aud, so tokens from another issuer or audience are accepted.
  • Using symmetric HS256 across many services, sharing the signing secret widely.
jwt.verify(token, publicKey, { algorithms: ["RS256"], issuer, audience });

Review these in security tests and prefer battle-tested libraries over hand-rolled token handling.

Candidate Response Strategy & Interview Tips

  1. Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
  2. Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
  3. Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
  4. Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.
Related Topics & Skills
Spotted an error or have an alternative solution?