<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>jwt.tooljo.com — blog</title><description>Long-form posts on JWT security, signing-key rotation, and modern auth alternatives.</description><link>https://jwt.tooljo.com/</link><language>en-us</language><item><title>JWT claims your auth team forgets to check (and how each one bit me)</title><link>https://jwt.tooljo.com/blog/jwt-claims-everyone-forgets/</link><guid isPermaLink="true">https://jwt.tooljo.com/blog/jwt-claims-everyone-forgets/</guid><description>iss, aud, jti, nbf, sub. The JWT spec defines these for a reason — but most production code only checks exp and the signature. Here&apos;s why each of the others matters.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item><item><title>fast-jwt CVE-2026-34950: how a regression re-enabled algorithm confusion</title><link>https://jwt.tooljo.com/blog/fast-jwt-cve-2026-34950/</link><guid isPermaLink="true">https://jwt.tooljo.com/blog/fast-jwt-cve-2026-34950/</guid><description>An algorithm-confusion bug in fast-jwt was patched in 2024, then partially re-introduced by a refactor. Here&apos;s the diff, the attack, and what to check in your own JWT code.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>