Cloudflare customers can now protect their APIs from broken authentication attacks by validating incoming JSON Web Tokens (JWTs) with API Gateway's JWT Validation. The release addresses feature requests for supporting the Bearer token format, creating multiple JWKS configs, validating JWTs sent in cookies, and excluding managed

8m read timeFrom blog.cloudflare.com
Post cover image
Table of contents
What’s new in this release?What is the threat?A primer on authentication and authorizationA primer on API access tokensWhat’s the structure of a JWT?Proper authentication and authorization stop API attacksMissing or broken authenticationExpired token reuseBroken Function Level Authorization attacks: Tampering with claimsDon’t other Cloudflare products do this?What’s next?

Sort: