Webinar

Are You Properly Using JWTs?

January 30, 2020

Webinar Thumb Preview-1024x585px copy

JSON Web tokens (JWTs) are used massively in API-based applications as access tokens or to transport information across services. Unfortunately, JWT are often mis-used and incorrectly handled. Massive data breaches have occurred in the last 18 months due to token leakage and lack of proper of validation.

This session focuses on best practices and real-world examples of JWT usage, where we cover:

    • Typical scenarios where using JWT is a good idea
    • Typical scenarios where using JWT is a bad idea!
    • Principles of Zero trust architecture and why you should always validate
    • Best practices to thoroughly validate JWTs and potential vulnerabilities if you don’t.
    • Use cases when encryption may be required for JWT

Speaker

Phil-webinar
Philippe Leothaud

CTO and Co-founder

 

Watch the Webinar

Browse the Deck

Latest Resources

BLOG

Vibe Coding Has a Security Debt Problem. Here’s How to Stop Inheriting It.

By Hugh Carroll | June 30, 2026

The numbers surrounding AI coding agents are no longer theoretical. A recent article from The Next Web investigating the Lovable breach suggests that between 40 and 62% of AI-generated code contains security vulnerabilities — and is being generated at 2.74 times the rate of human-written code. In Q1 […]

NEWS

42Crunch and GitHub Copilot Bring Deterministic API Security Guardrails to Agentic DevSecOps

By Hugh Carroll | June 16, 2026

Breakthrough integration enables real-time detection and remediation of API vulnerabilities in AI-driven development workflows at machine speed   San Francisco, CA — June 16, 2026 — 42Crunch, the leading API security platform for the agentic era, today announced the availability of the 42Crunch API Security Testing Plugin for […]

DataSheet

Product Datasheet Addressing API Security Challenges

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform