Skip to main content

Posts

Featured

Stable Redirects for Auth Testing: Debugging JWT Vulnerabilities with Persistent Subdomains

If you spend your days building Identity and Access Management (IAM) systems or hunting for bugs in authentication flows, you are likely intimately familiar with the pain of the ephemeral tunnel. You set up your local development environment, spin up a tunnel to route public traffic to your localhost, and start testing a complex OAuth 2.0 callback or a JSON Web Token (JWT) verification flow. Then your laptop goes to sleep, your Wi-Fi drops for three seconds, or you accidentally hit Ctrl+C. The tunnel restarts. Your generated URL changes from https://a1b2c3d4.random-tunnel.com to https://e5f6g7h8.random-tunnel.com . Suddenly your carefully configured Identity Provider (IdP) allowlists, CORS policies, and redirect URIs are broken. You have to log back into Auth0, Okta, or Keycloak, update the callback URLs, and start your testing sequence all over again. When testing complex security vulnerabilities — such as JWT algorithm confusion or malicious JWKS ( jku ) header injection — this c...

Latest Posts

Your Localhost Is Not Private: Securing Developer Environments Against Localhost SSRF and DNS Rebinding

Testing Local RAG Pipelines: Routing Production Webhooks to Local Vector Databases

The "No-Root" Enterprise Compliance Angle: Securing Developer Tunnels in 2026