In more detail
The parts are header, payload and signature, joined by dots. The payload is only encoded, not encrypted, so anyone can read it; the signature stops it being altered. Servers verify the signature and the exp claim on each request. See How JSON Web Tokens (JWT) Work.