Webinar

Are You Properly Using JWTs?

January 30, 2020

Webinar Thumb Preview-1024x585px copy

JSON Web tokens (JWTs) are used massively in API-based applications as access tokens or to transport information across services. Unfortunately, JWT are often mis-used and incorrectly handled. Massive data breaches have occurred in the last 18 months due to token leakage and lack of proper of validation.

This session focuses on best practices and real-world examples of JWT usage, where we cover:

    • Typical scenarios where using JWT is a good idea
    • Typical scenarios where using JWT is a bad idea!
    • Principles of Zero trust architecture and why you should always validate
    • Best practices to thoroughly validate JWTs and potential vulnerabilities if you don’t.
    • Use cases when encryption may be required for JWT

Speaker

Phil-webinar
Philippe Leothaud

CTO and Co-founder

 

Watch the Webinar

Browse the Deck

Latest Resources

BLOG

The State of API Security Report 2026

By Hugh Carroll | February 16, 2026

The State of API Security in 2026: Analysis of real-world API vulnerabilities Our recently published State of API Security Report 2026﹡ delivers a data-driven analysis of real-world API vulnerabilities, showing how common mistakes in implementation translate into security risks in production. It paints a clear and, at times, […]

NEWS

42Crunch Recognized by Enterprise Security Leaders as API Security Emerges as Critical AI control layer in State of AI Security Report

By Hugh Carroll | March 4, 2026

San Francisco, CA – March 4 2026 – 42Crunch, the API security platform company, today highlighted its growing visibility among enterprise security leaders following the release of the Sagetap State of AI in Cybersecurity Report 2026,  which analyzes real security buying initiatives from CISOs and senior security executives. The […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform