A common accident in APIs that receive JWTs is confusing the ability to "decode" a token with the ability to "validate" it.
Critical vulnerabilities exist in several JSON Web Token (JWT) libraries – namely the JavaScript and PHP versions – that could let an attacker bypass the verification step. Critical vulnerabilities ...