Understanding JWTs: How Token-Based Authentication Works

A JWT is a signed, three-part token used for authentication — its header and payload can be decoded by anyone without a secret, but verifying its signature is what actually proves it hasn't been tampered with.

Key Points

  • A JWT has three parts: header, payload, and signature
  • Decoding a JWT's payload requires no secret key — never put sensitive data in it
  • Verifying a JWT's signature is what actually establishes trust
  • Token expiry limits the damage if a token is ever leaked or stolen

What a JWT is

A JSON Web Token (JWT) is a compact, text-based format for representing a set of claims — such as “this user is logged in as X” — that can be verified and trusted because it is digitally signed. JWTs are widely used for authentication and authorization in modern web and mobile applications.

The three parts of a JWT

A JWT consists of three parts separated by dots: a header (describing the token type and signing algorithm), a payload (the actual claims, such as user ID or expiry time), and a signature (proving the token hasn’t been tampered with). The header and payload are just Base64-encoded JSON — readable by anyone — while the signature is what actually makes the token trustworthy.

A critical distinction: decoding vs verifying

Anyone can decode a JWT’s header and payload without any secret key, because they are only encoded, not encrypted. This means a JWT should never contain sensitive secrets in its payload. Verifying a JWT — confirming its signature is valid and it hasn’t been tampered with or expired — requires the correct signing key or public key, and is what actually determines whether a token should be trusted.

Why JWT expiry matters

Most JWTs include an expiry claim so that a stolen or leaked token becomes useless after a limited time. A system that doesn’t check expiry, or issues tokens with very long lifespans, increases the impact of a token being compromised.

Common uses

  • Authenticating API requests without needing a database lookup on every request
  • Passing user identity and permissions between services in a system
  • Single sign-on (SSO) flows between related applications

Frequently Asked Questions

Is a JWT encrypted?

No, by default a JWT's header and payload are only encoded, not encrypted, so anyone can read their contents without a secret key.

Why do JWTs usually have an expiry time?

So that if a token is ever leaked or stolen, it becomes useless after a limited window rather than remaining valid indefinitely.

Explore More

Browse every free calculator and tool, or find more practical guides.