Exercise sec-jwt — a JWT verifier that rejects alg=none and key confusion

JWT & key confusion showed you two verifiers side by side: a naive one that trusts whatever the token's own header claims, and a safe one that never lets the token choose how it gets checked. This exercise is the safe one — verify(token, keys, allowed_algs) — built from scratch against 8 checks, four of which are the exact attacks the lesson walked through.

~75 minruns in the browser 8 checkssec-jwt

What you're building

The checks are ordinary Python and ship with the page like everything else on a static site — open devtools and you can read every one. Check 3 signs a token with the RSA public key used as an HMAC secret: a verifier that dispatches purely on the header's alg (never checking the key's own kind) accepts it — that's the check that actually catches key confusion, not just "wrong signature".

If you get stuck