The external JWT authentication documentation tells API clients to create a fresh token for every request…
The external JWT authentication documentation tells API clients to create a fresh token for every request…: a task in MiMo-V2.6-RL-oss: Agentic RL Environments (MiMo RL release). A captured, still-valid API token can therefore be replayed. Add replay protection at the decoder boundary without…
The task
A captured, still-valid API token can therefore be replayed. Add replay protection at the decoder boundary without changing the existing issuer lookup, signing algorithm, iat/exp checks, clock-skew handling, or maximum token lifetime. Every otherwise-valid API-key JWT must…
Part of XiaomiMiMo/MiMo-V2.6-RL-oss.