Glossary · Security & Resilience
What is a JWT (JSON Web Token)?
Short answer
A JWT (JSON Web Token) is a compact, signed token for passing claims, such as who a user is and when the token expires, between systems. It has three Base64URL parts: a header, a payload and a signature. The receiver checks the signature to confirm the token wasn’t altered. JWTs are widely used for API authentication and single sign-on.
The three parts
- Header: the signing algorithm, such as
HS256(shared secret) orRS256(public/private key pair). - Payload: claims like
sub(user id),exp(expiry),iss(issuer) andaud(audience). - Signature: proves the header and payload were issued by someone holding the key.
The payload is only encoded, not encrypted: anyone holding the token can read it, so never put secrets in it. You can inspect a token safely in the browser with the JWT Decoder & Verifier.
Common mistakes
- Not verifying the signature, or accepting the
nonealgorithm. - Long-lived tokens with no way to revoke them; keep access tokens short (minutes) and use refresh tokens.
- Skipping
issandaudchecks, so a token for one service works on another. - Storing tokens where scripts can read them; prefer httpOnly cookies for browser sessions.
JWT or sessions?
For a traditional web app, server-side sessions are simpler and easy to revoke. JWTs suit APIs called by mobile apps, third parties or other services, where stateless verification helps.

