Security & Auth interview question

What is a JWT and what are its security pitfalls?

Short answer

A JSON Web Token is a compact, signed token with three base64url parts: header, payload (claims) and signature. Servers verify the signature to trust the claims without a database lookup. JWTs are signed, not encrypted, so never put secrets in them; keep them short-lived, validate algorithm, issuer, audience and expiry, and plan for revocation.

Common pitfalls

  • Accepting the “none” algorithm or letting the token choose the algorithm.
  • Long-lived tokens that cannot be revoked after a compromise.
  • Storing tokens where scripts can read them, increasing XSS impact.
  • Skipping audience and issuer checks.

Sessions vs JWTs

Server-side sessions are easy to revoke and keep data private. JWTs suit distributed verification between services. Many systems combine short-lived JWT access tokens with revocable refresh tokens.

How to answer it in an interview

  • Stress “signed, not encrypted”.
  • Describe a revocation approach such as short expiry plus refresh-token rotation.

Walk into your next interview prepared

Start free, install the Windows app and run a practice session today.