Glossary · Security & Resilience

What is a JWT (JSON Web Token)?

Short answer

A JWT (JSON Web Token) is a compact, signed token for passing claims, such as who a user is and when the token expires, between systems. It has three Base64URL parts: a header, a payload and a signature. The receiver checks the signature to confirm the token wasn’t altered. JWTs are widely used for API authentication and single sign-on.

The three parts

  • Header: the signing algorithm, such as HS256 (shared secret) or RS256 (public/private key pair).
  • Payload: claims like sub (user id), exp (expiry), iss (issuer) and aud (audience).
  • Signature: proves the header and payload were issued by someone holding the key.

The payload is only encoded, not encrypted: anyone holding the token can read it, so never put secrets in it. You can inspect a token safely in the browser with the JWT Decoder & Verifier.

Common mistakes

  • Not verifying the signature, or accepting the none algorithm.
  • Long-lived tokens with no way to revoke them; keep access tokens short (minutes) and use refresh tokens.
  • Skipping iss and aud checks, so a token for one service works on another.
  • Storing tokens where scripts can read them; prefer httpOnly cookies for browser sessions.

JWT or sessions?

For a traditional web app, server-side sessions are simpler and easy to revoke. JWTs suit APIs called by mobile apps, third parties or other services, where stateless verification helps.

Published · Updated · By · All terms

Go deeper