Old JWT Verifiers Ignore a New Restricting Claim, So Restrict by Narrowing scope

The JWT specification tells verifiers to ignore claims they do not understand. That is harmless for claims that grant things and dangerous for claims that restrict them. Four ways to cap what a client kind may hold, tested with a small issuer and three verifiers, and the one I would pick.

September 17, 2026 | 8 min

Separate Authentication from What an Actor May Do

Designing API authentication and role-based authorization with actors, route permissions, and separate credentials for people and machines.

August 11, 2026 | 14 min