Feature docs · Website security · Module: jwt-analysis
JWT Analysis is a Guardbee scan module under website security. Finds JWT-shaped tokens in page/API samples and flags alg:none, long exp, and secret claims.
What does it check?
Finds JWT-shaped tokens in page/API samples and flags alg:none, long exp, and secret claims. Results appear in the dashboard and scan detail as score, findings, and recommended actions.
Business impact
Weak JWTs enable account takeover and privilege abuse.
Guardbee presents risk, impact, and priority — so product, legal, and engineering share one screen.
How to run it
- Create a Guardbee account (14-day free trial)
- Add a brand / URL
- Select JWT Analysis under Website security
- Run the scan; optionally explain findings with BeeAI
Related docs
Run this module now
Use JWT Analysis with no scan quota. Start with a 14-day free trial.
Frequently asked questions
Is JWT Analysis required?
No. Pick modules as needed; there is no scan quota — limits are active brands.
Is scanning destructive?
No. Guardbee uses controlled, read-only, limited requests.
Does it work with BeeAI?
Yes. After a scan, BeeAI can summarize findings in business language.