Securing REST APIs: OAuth2 vs JWT Weaknesses

Authors

  • Kavya Muppaneni Senior Software Engineer at HCL Global Systems, USA. Author

DOI:

https://doi.org/10.64137/3107-9458/ICACSIS-105

Keywords:

REST APIs, API Security, OAuth2, JSON Web Token (JWT), Authentication, Authorization, Web Security, Access Control

Abstract

With the ongoing digital transformation, modern software applications are increasingly using REST APIs to facilitate communications among distributed systems, mobile apps, and cloud services, turning API security into one of the most pressing issues in the digital world today. Since APIs are a common route to access sensitive data and key functionalities, improper controls of their authentication and authorization mechanisms can be exploited to cause serious damages. OAuth2 and JSON Web Tokens (JWT) are arguably two of the most popular technologies by which REST APIs can be safeguarded; consequently, they have set the standard for the industry because of their scalability and flexibility. OAuth2 sets up an authorization delegation architecture under which a client can be given access without having to expose the credentials, whereas the JWT functions as a compact, self-contained token carrier of the claims between two parties. Due to the fact that they have been adopted en masse, it might be assumed that they do not have any security risks, however, if for some reason the design, configuration or implementation are done incorrectly, they will each have a market share of such risks. The paper documents the main security failures of OAuth2 and JWT to token leakages, insufficient token validations, insecure token storages, over-privileged scopes, replay attacks, and algorithm-related vulnerabilities. An extensive exposure of OAuth2 and JWT on various aspects of security such as confidentiality, integrity, token lifecycle management, and attack surface is done through a comparative analysis methodology. Besides, a case study of the real world is incorporated to expose the impact of some common misconfiguration and design choices in security frameworks otherwise thought to be strong. It is demonstrated that the major problems are not the result of the standards themselves but rather the misuse of developers, lack of threat modeling and inadequate enforcement of best practices. This paper sheds light on the security weaknesses of OAuth2 and JWT, depicts the real risks faced by REST APIs today, and provides some guidance towards better decision making from the security point of view by architects and developers in the selection and implementation of API authentication strategies.

References

[1] ELHejazi, Mahmoud F., and Wisam HA Muragaa. "Improving the Security and Reliability of SDN Controller REST APIs Using JSON Web Token (JWT) with OpenID and auth2. 0." 2024 IEEE 4th International Maghreb Meeting of the Conference on Sciences and Techniques of Automatic Control and Computer Engineering (MI-STA). IEEE, 2024.

[2] Talakola, Swetha, and Sai Prasad Veluru. "Managing Authentication in REST Assured OAuth, JWT and More." International Journal of Emerging Trends in Computer Science and Information Technology 4.4 (2023): 66-75.

[3] Gbenle, Toluwase Peter, et al. "Applying OAuth2 and JWT Protocols in Securing Distributed API Gateways: Best Practices and Case Review." (2022).

[4] Beshiri, A. R. B. Ë. R., A. N. A. S. T. A. S. Mishev, and I. V. A. N. Chorbev. "Security issues in the RESTful API (service) using OAuth 2.0 for authentication and authorization." Proc. Int. Conf. Engineering Technologies. 2021.

[5] Ferry, Eugene, John O Raw, and Kevin Curran. "Security evaluation of the OAuth 2.0 framework." Information & Computer Security 23.1 (2015): 73-101.

[6] Alghawli, Abed Saif Ahmed. "Analysis of Authentication Methods and Secure Web Application Realization With an Integrated Authentication System." Appl. Math 19.5 (2025): 1027-1038.

[7] Helenius, Marko, and Minna Vallius. "REST API SECURITY: TESTING AND ANALYSIS." (2022).

[8] Kumar, Ritesh. "Enhancing API Security: A Comparative Analysis of OAuth 2.0, OpenID Connect, and SAML."

[9] Jangam, Sandeep Kumar, Nagireddy Karri, and Partha Sarathi Reddy Pedda Muntala. "Advanced API Security Techniques and Service Management." International Journal of Emerging Research in Engineering and Technology 3.4 (2022): 63-74.

[10] Siriwardena, Prabath. Advanced API security: OAuth 2.0 and beyond. Apress, 2019.

[11] Mendoza Jiménez, Francisco. Securing a REST API Server. MS thesis. Universitat Politècnica de Catalunya, 2022.

[12] Visočnik, Vid. Comparison of JWT and OAuth 2.0 for authorisation and authentication in rest services. Diss. Univerza v Mariboru, Fakulteta za elektrotehniko, računalništvo in informatiko, 2018.

[13] Phanireddy, Sandeep. "Securing RESTful APIs in Microservices Architectures: A Comprehensive Threat Model and Mitigation Framework." International Journal of Emerging Research in Engineering and Technology 4.2 (2023): 64-73.

[14] Ali, AzraJabeen Mohamed. "Ensuring Secure Access: Authentication and Authorization in ASP .NET Web API." (2022).

[15] Badhwar, Raj. "Intro to API security-issues and some solutions!." The CISO’s Next Frontier: AI, Post-Quantum Cryptography and Advanced Security Paradigms. Cham: Springer International Publishing, 2021. 239-244.

Downloads

Published

2025-11-12

How to Cite

Securing REST APIs: OAuth2 vs JWT Weaknesses. (2025). International Journal of Computer Science and Engineering Innovations, 49-59. https://doi.org/10.64137/3107-9458/ICACSIS-105