Review agent · Identity & access

Authentication & JWT

Checks that identity, tokens and sessions are actually verified and hardened.

auth/session.js1jwt.verify(token, secret, {2 algorithms: ["HS256", "none"],3 ignoreExpiration: true,4});Authwhat this review answersAlgorithm pinned, no alg=none?Signature and expiry verified?Cookies Secure, HttpOnly, SameSite?$ verdict REAL ISSUE$ fix pin the algorithm, enforce exp▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

If authentication is wrong, every other control sits on sand. OWASP lists it as A07 (Identification and Authentication Failures), and JWT mistakes such as unverified signatures or alg confusion recur in real systems.

Auth code is easy to read as correct and hard to verify by pattern. This agent checks the specific properties that matter — pinned algorithms, verified signatures and expiry, session regeneration, OAuth state — rather than just spotting the word 'jwt'.

What it checks

  • JWT algorithm pinning (no none / alg confusion), signature and exp verification, weak secrets
  • Session fixation: regenerating the session on login
  • Cookie attributes: Secure, HttpOnly, SameSite
  • OAuth state / PKCE and redirect-URI validation
  • Endpoints missing authentication entirely

When it marks a finding as a likely false positive

  • Tokens are verified with a pinned algorithm and expiry
  • Session handling follows the framework's secure defaults

The fix it suggests

  • Verified tokens with a pinned algorithm
  • Session regeneration and server-side invalidation
  • Hardened cookie attributes and PKCE

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Does it check OAuth flows?

Yes, as far as the code shows: state or PKCE use and redirect-URI validation are part of its review.

Related agents

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Authentication & JWT agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free