What is a JWT?
A signed, compact token that carries claims between systems.
A JSON Web Token (JWT), pronounced "jot", is a compact string that carries information (called claims) in JSON, and is usually signed so the receiver can detect tampering. It is defined in RFC 7519.
What it looks like
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiQW5hIn0.SflKxw...Three parts separated by dots. The first two start with eyJ because they are Base64URL text of a JSON object that begins with {".
The typical use
- You log in with your credentials.
- The server verifies them and returns a signed JWT that says who you are and what you may do.
- Your app sends the JWT with later requests, usually in the
Authorization: Bearer ...header. - The API checks the signature and the claims instead of asking a database each time.
Why people like them
- Stateless: the server does not need a session store to validate one.
- Portable: different services can verify the same token.
- Standard: libraries exist for every language.
Signed is not secret
CarefulA normal JWT is signed, not encrypted. Anyone who has it can read the payload. Never put passwords or private data in it.
NotePaste any token into the JWT decoder to see this for yourself. It decodes locally in your browser.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.