What a JWT is
A JSON Web Token (JWT) is a compact, text-based format for representing a set of claims — such as “this user is logged in as X” — that can be verified and trusted because it is digitally signed. JWTs are widely used for authentication and authorization in modern web and mobile applications.
The three parts of a JWT
A JWT consists of three parts separated by dots: a header (describing the token type and signing algorithm), a payload (the actual claims, such as user ID or expiry time), and a signature (proving the token hasn’t been tampered with). The header and payload are just Base64-encoded JSON — readable by anyone — while the signature is what actually makes the token trustworthy.
A critical distinction: decoding vs verifying
Anyone can decode a JWT’s header and payload without any secret key, because they are only encoded, not encrypted. This means a JWT should never contain sensitive secrets in its payload. Verifying a JWT — confirming its signature is valid and it hasn’t been tampered with or expired — requires the correct signing key or public key, and is what actually determines whether a token should be trusted.
Why JWT expiry matters
Most JWTs include an expiry claim so that a stolen or leaked token becomes useless after a limited time. A system that doesn’t check expiry, or issues tokens with very long lifespans, increases the impact of a token being compromised.
Common uses
- Authenticating API requests without needing a database lookup on every request
- Passing user identity and permissions between services in a system
- Single sign-on (SSO) flows between related applications