A Valid Signature From the Wrong Issuer
| 37 min read
AI Security n8n validated token signatures against trusted keys without checking that the key belonged to the claimed issuer, letting one tenant resolve into another through matching account names. A look at issuer confusion, RFC 9207, and why agent platforms are especially exposed.