Tampering JWT

This code shows that jwt validation fails if someone tries to tamper it

Requirements

  • Linux or OSX
  • python3.5+,
  • pip
  • virtualenv

Setup

$ virtualenv venv
$ . venv/bin/activate
$ pip install --upgrade pip
$ pip install -r requirements.txt
$ deactivate

Run

$ . venv/bin/activate
$ python app.py
$ deactivate