4 ms·
You can decode the token without the secret. Generally JWT is not encrypted and you shouldn't put sensitive info inside. But you can't modify the token without
by curried_haskell 10y ago
You can decode the token without the secret. Generally JWT is not encrypted and you shouldn't put sensitive info inside. But you can't modify the token without knowing the secret, because you won't have a valid signature.
So I can hand out session tokens, and you can't modify the user ID or the expiration time unless you know the secret.