Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

L9 · IDENTITY FUNDAMENTALS

Reading is not validating

Decode a token from your test tenant, then submit it unchanged and tampered to a verifier.

Planned

Steps

  1. Get a token from your test tenant and decode it with the tenant's Token Decoder.

    What the server will check: Nothing to check. Anyone holding the token can read it.

  2. Submit the unchanged token to the lab verifier.

    What the server will check: The verifier accepted it.

  3. Change one claim and submit it again.

    What the server will check: The verifier rejected it because the signature no longer matches.

    Decoding shows what a token claims. Only validation shows whether to believe it.

When it opens

This lab is planned. It opens when these are in place:

  • Lab setup and cleanup in your test tenant
  • A lab token verifier

The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.

Learn the theory

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab