JWT security best practices for issuers

Most JWT guidance targets verifiers. Issuers make decisions that matter just as much: key strength, lifetimes, audiences and what goes into the payload. These practices follow RFC 8725.

Keys

Claims

Explicit typing

If one issuer produces different kinds of JWT (access tokens, ID tokens, logout tokens), set a distinct typ such as at+jwt and have verifiers check it (RFC 8725 §3.11). This stops one token type from being accepted in place of another.

Operations

Produce a full set of should-reject tokens for your API test suite in one click.

Generate negative tests

Related: HS256 secrets · RS256 keys