Review agent · Identity & access
Authentication & JWT
Checks that identity, tokens and sessions are actually verified and hardened.
Illustrative example of how this agent reviews a finding.
Why this agent matters
If authentication is wrong, every other control sits on sand. OWASP lists it as A07 (Identification and Authentication Failures), and JWT mistakes such as unverified signatures or alg confusion recur in real systems.
Auth code is easy to read as correct and hard to verify by pattern. This agent checks the specific properties that matter — pinned algorithms, verified signatures and expiry, session regeneration, OAuth state — rather than just spotting the word 'jwt'.
What it checks
- JWT algorithm pinning (no none / alg confusion), signature and exp verification, weak secrets
- Session fixation: regenerating the session on login
- Cookie attributes: Secure, HttpOnly, SameSite
- OAuth state / PKCE and redirect-URI validation
- Endpoints missing authentication entirely
When it marks a finding as a likely false positive
- Tokens are verified with a pinned algorithm and expiry
- Session handling follows the framework's secure defaults
The fix it suggests
- Verified tokens with a pinned algorithm
- Session regeneration and server-side invalidation
- Hardened cookie attributes and PKCE
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Does it check OAuth flows?
Yes, as far as the code shows: state or PKCE use and redirect-URI validation are part of its review.
Related agents
- Access control & authorization — Checks that each sensitive action is authorized for the specific object, not just a logged-in user.
- Directory & LDAP integration — Reviews Active Directory and LDAP code for injection, cleartext binds and hard-coded credentials.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Authentication & JWT agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free