Feature docs · Website security · Module: jwt-analysis
JWT Analysis is a Guardbee scan module under website security. Finds JWT-shaped tokens in page/API samples and flags alg:none, long exp, and secret claims.
What does it check?
Finds JWT-shaped tokens in page/API samples and flags alg:none, long exp, and secret claims. Results appear in the dashboard and scan detail as score, findings, and recommended actions.
Business impact
Weak JWTs enable account takeover and privilege abuse.
Guardbee presents risk, impact, and priority — so product, legal, and engineering share one screen.
How to run it
- Create a Guardbee account (25 credits for new accounts)
- Add a brand / URL
- Select JWT Analysis under Website security
- Run the scan; optionally explain findings with BeeAI
Related docs
Frequently asked questions
Is JWT Analysis required?
No. Pick modules as needed; you only spend credits on what you run.
Is scanning destructive?
No. Guardbee uses controlled, read-only, limited requests.
Does it work with BeeAI?
Yes. After a scan, BeeAI can summarize findings in business language.