
3/5/2024 · John Cosgrove
What this post added
This post announces the General Availability (GA) of JWT validation in Cloudflare's API Gateway. It details the improvements made since the beta release, including support for Bearer token format, multiple JWKS configurations, validation of JWTs in cookies, and the ability to exclude managed endpoints. The post also explains the threat of broken authentication and authorization, provides a primer on JWT structure and its security benefits, and illustrates how JWT validation protects against missing/broken authentication and expired token reuse.