Home / Companies / Descope / Blog / October 2026

October 2026 Summaries

2 posts from Descope

Filter
Month: Year:
Post Summaries Back to Blog
No summary generated yet.
Oct 09, 2026 2,504 words in the original blog post.
JSON Web Tokens (JWTs) are commonly used credentials composed of Base64url-encoded header, payload, and signature segments, with readable claims such as issuer, audience, user identity, roles, and expiration times. Decoding reveals these claims but provides no assurance that they are authentic, while verification uses a trusted public key or shared secret to validate the signature, enforce an algorithm allowlist, and check claims including expiration, issuer, audience, and not-before time. JWT authentication typically involves issuing a signed access token after login, transmitting it as a Bearer token, and verifying it on every request without requiring a server-side session lookup. The discussion contrasts stateless JWTs with revocable server-stored session tokens and distinguishes short-lived access tokens from longer-lived refresh tokens, which should be protected through HttpOnly cookies, rotation, and reuse detection. Common security failures include trusting decoded claims without verification, accepting insecure algorithms, using weak secrets, issuing long-lived tokens without revocation controls, and storing tokens in localStorage where cross-site scripting can expose them. Descope promotes browser-based token decoding and verification tools alongside SDKs and configurable session, refresh-token, and cookie-management features.
Oct 01, 2026 2,874 words in the original blog post.