Stable Redirects for Auth Testing: Debugging JWT Vulnerabilities with Persistent Subdomains
If you spend your days building Identity and Access Management (IAM) systems or hunting for bugs in authentication flows, you are likely intimately familiar with the pain of the ephemeral tunnel. You set up your local development environment, spin up a tunnel to route public traffic to your localhost, and start testing a complex OAuth 2.0 callback or a JSON Web Token (JWT) verification flow. Then your laptop goes to sleep, your Wi-Fi drops for three seconds, or you accidentally hit Ctrl+C. The tunnel restarts. Your generated URL changes from https://a1b2c3d4.random-tunnel.com to https://e5f6g7h8.random-tunnel.com . Suddenly your carefully configured Identity Provider (IdP) allowlists, CORS policies, and redirect URIs are broken. You have to log back into Auth0, Okta, or Keycloak, update the callback URLs, and start your testing sequence all over again. When testing complex security vulnerabilities — such as JWT algorithm confusion or malicious JWKS ( jku ) header injection — this c...