← Back to the module

Knowledge check

JSON Web Tokens & API authentication

3 questions testing what you just read — no login, no tracking, just immediate feedback.

Question 1 of 3

What does a JWT's signature actually protect?

Question 2 of 3

What makes the "algorithm confusion" attack against JWTs possible?

Question 3 of 3

Compared to an opaque session token, what's a key limitation of JWTs?

0 / 3 answered