In this recipe, we need to generate JWT tokens. Therefore, we will use the OneLogin software to assist with this task. In order to complete this recipe, browse to the OneLogin website: https://www.onelogin.com/. Click the Developers link at the top and then click the GET A DEVELOPER ACCOUNT link (https://www.onelogin.com/developer-signup).
After you sign up, you will be asked to verify your account and create a password. Please perform these account setup tasks prior to starting this recipe.
Using the OneLogin SSO account, we will use two Burp extensions to examine the JWT tokens assigned as authentication by the site.