More detailed explanation here: https://github.com/dgrijalva/jwt-go/issues/428 How should we approach a fix? There is a `v4.0.0-preview1` version in dgrijalva/jwt-go that apparently fixes this, and a bunch of PRs. There was a fix in this fork, https://github.com/form3tech-oss/jwt-go by @Waterdrips and co. as well.