Glossary Security

JWT

A JWT (JSON Web Token) is a compact, signed token made of three Base64URL parts that carries claims such as who a user is and when the token expires.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

The parts are header, payload and signature, joined by dots. The payload is only encoded, not encrypted, so anyone can read it; the signature stops it being altered. Servers verify the signature and the exp claim on each request. See How JSON Web Tokens (JWT) Work.

Try these tools

See also

  • Glossary HMAC
    HMAC (hash-based message authentication code) is a hash computed with a secret key.
  • Glossary Base64
    Base64 is an encoding that writes any binary data using only 64 safe text characters (A-Z, a-z, 0-9, + and /).
  • Glossary OAuth
    OAuth is a standard that lets one app act on your behalf at another service, such as "Sign in with Google".
  • Guide How JSON Web Tokens (JWT) Work
    The three parts of a JWT with a real decoded example, the registered claims, how servers verify the signature.
AdSense Placeholder
Slot: footer_leaderboard