Prompt

How do I test JWT-protected APIs and check permission boundaries?

Technology / Testing & QA1 observationLast seen Oct 6, 2026

Latest observation

Oct 6, 2026OpenAI APIWeb search: off

To test JWT-protected APIs and verify permission boundaries, you want to validate both authentication and authorization.

1) Test with different JWTs

Create tokens that represent different real-world roles/scopes:

  • Valid token with full privileges
  • Valid token with limited privileges
  • Expired token
  • Malformed token
  • Token with wrong issuer/audience
  • Token signed with the wrong key
  • Token with missing or insufficient scopes/roles

Then call each endpoint with each token and confirm the API returns the expected result.

2) Verify expected HTTP responses

Typical outcomes:

  • 200/201 → allowed
  • 401 Unauthorized → missing/invalid/expired token
  • 403 Forbidden → authenticated but not allowed for this resource/action

A good boundary test checks that:

  • A token valid for reading cannot create/update/delete
  • A token for one tenant/user cannot access another tenant/user’s data
  • A role like viewer cannot use admin-only endpoints

3) Test object-level authorization

This is where many bugs happen.

Examples:

  • User A’s token should not access /users/B/profile
  • Tenant A’s token should not read /tenants/B/orders/123
  • A user with “manager” role should still not modify records outside their assigned region/team

This ensures permissions are enforced on the resource instance, not just the endpoint.

4) Test claims that drive authorization

Inspect whether the API correctly validates JWT claims such as:

  • iss (issuer)
  • aud (audience)
  • exp (expiration)
  • nbf (not before)
  • sub (subject/user)
  • scope or roles
  • tenant/org identifiers like tid, org_id, realm_access

Make sure the API doesn’t trust unvalidated custom claims.

5) Test token tampering

Modify parts of the JWT and confirm rejection:

  • Change alg to none if applicable
  • Alter payload without resigning
  • Swap roles/scopes in the payload
  • Reuse a token after logout if revocation is expected

The server should reject any tampered token.

6) Check endpoint-by-endpoint access matrix

Build an access matrix like this:

Role/ScopeGET /itemsPOST /itemsDELETE /items/1
viewerAllowedForbiddenForbidden
editorAllowedAllowedForbidden
adminAllowedAllowedAllowed

Run tests against each combination.

7) Automate with negative tests

Use tools like:

  • Postman/Newman
  • pytest + requests
  • pytest + httpx
  • RestAssured
  • JUnit
  • OWASP ZAP for security testing

Automated tests should include both positive and negative cases.

Example test cases

  • No token → 401
  • Expired token → 401
  • Token with correct auth but wrong role → 403
  • Token for user A accessing user B’s data → 403
  • Admin token accessing admin endpoint → 200

8) Practical checklist

For each endpoint, verify:

  • Requires a token
  • Rejects invalid/expired tokens
  • Enforces issuer/audience
  • Enforces role/scope permissions
  • Enforces tenant/object ownership boundaries
  • Doesn’t leak data in error messages
  • Logs authorization failures appropriately

If you want, I can also give you:

  1. a Postman test collection structure,
  2. a pytest example, or
  3. a permission boundary test matrix template.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.