DEV Community

Discussion on: 7 Best Practices for JSON Web Tokens

Collapse
 
neilmadden profile image
Neil Madden

The issue is with just using RSA encryption without signing/hmac. Encryption is done using the public key, which means anyone with that public key could then create a valid token.

Collapse
 
jthughey profile image
Justin Hughey

Thank you for the clarification!