Skip to main content

SID-AUTH-02 — JWT Bearer Token Session Management

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupAuthentication Controls

Description

Authenticated sessions managed via JWT bearer tokens with configurable TTL. Token middleware validates every request, extracting user_id and tenant_id claims. Supports token blacklisting. Admin API uses separate constant-time token validation.

Components

  • Wallet Backend (Go)

Source References

Audit Findings

FindingSeverityStatus
EN-S-4 — Partial wallet unit security and lifecyclemediumin progress
EN-P-5 — Partial user authentication and session controlshighin progress
ISO-T-5 — Partial endpoint and privileged access controlsmediumopen