Side by side
JWTvsOAuth
What is the difference between JWT and OAuth?
Updated 3 min read7 differences
In short
OAuth is a framework for giving an app limited access to user data; a JWT is a token format. They aren't rivals: OAuth often issues JWT access tokens.
JWT
JSON Web Token
A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
Read the page on JWTOAuth
OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
Read the page on OAuthJWT and OAuth compared
| Aspect | JWT | OAuth |
|---|---|---|
| What it is | A token format | An authorization framework: a set of flows |
| Answers | What a token says, and whether it was changed | How an app gets permission to call an API for a user |
| Defined in | RFC 7519 | RFC 6749 (OAuth 2.0) |
| Made of | A header, claims such as subject and expiry, and a signature | Roles: client, user, authorization server, resource server |
| Used for | Access tokens, ID tokens and session tokens | Delegated access, such as an app reading your calendar |
| Works without the other? | Yes, wherever signed tokens are needed | Yes, with opaque tokens checked by the server |
| Common mistake | Decoding without verifying the signature | Using it as a login protocol on its own |
The difference, explained
A JSON Web Token (JWT) is a format: a signed string carrying claims, such as who the user is and when the token expires. OAuth 2.0 is an authorization framework: a set of flows by which an app gets the user's permission to call an API on their behalf, without ever seeing their password.
They meet where OAuth hands out tokens. After the user approves an app, the authorization server issues an access token, and the API accepts it with each request. OAuth doesn't say what that token looks like: it can be a random string the API checks with the server, or a JWT the API verifies by itself from its signature. Many providers choose JWTs for that reason, and OpenID Connect, built on OAuth, always uses a JWT for its ID token.
So asking JWT or OAuth is like asking passport or border control: one is a document, the other is the process that decides who gets one and what it allows. You can use JWTs without OAuth, for example as the session tokens of your own login, and OAuth without JWTs, with opaque tokens.
Two mistakes are common. The first is treating OAuth as login: OAuth answers what an app may do, not who the user is, and signing users in with another provider is done with OpenID Connect on top of OAuth. The second is trusting a JWT without checking its signature, issuer, audience and expiry: decoding a token is not verifying it.
Which one should you use?
Choose JWT when…
- Services need to verify a token on their own, without calling a central server.
- You are deciding what goes inside a token and how it is signed.
- You need a compact, signed way to pass identity between your own services.
Choose OAuth when…
- A third-party app needs limited access to a user's data in your service.
- Users should grant and revoke permissions without sharing a password.
- You want standard flows that existing clients and libraries already support.
Verifying a JWT vs starting an OAuth flow
// JWT: decoding shows the claims, verifying proves they are genuine
import { jwtVerify } from "jose";
const { payload } = await jwtVerify(token, publicKey, {
issuer: "https://auth.example.com",
audience: "orders-api",
});
console.log(payload.sub, payload.scope); // who, and what they may do// OAuth: send the user to approve, then swap the code for tokens
const url = new URL("https://auth.example.com/authorize");
url.search = new URLSearchParams({
response_type: "code",
client_id: CLIENT_ID,
redirect_uri: "https://app.example.com/callback",
scope: "orders:read",
state,
code_challenge, // PKCE
code_challenge_method: "S256",
});
location.href = url; // the user signs in and approves on the provider's pageReaders ask
Is OAuth the same as OpenID Connect?
No. OpenID Connect is a layer on top of OAuth 2.0 that adds login: an ID token, which is a JWT, tells the app who the user is.
Are OAuth access tokens always JWTs?
No. The specification leaves the format open. Some providers issue JWTs that APIs can verify locally; others issue opaque strings that the API checks with the authorization server, which makes revoking them easier.
Do I need OAuth for my own app's login?
Not necessarily. When your own users sign in to your own app, a session or a token you issue yourself is enough. OAuth matters when other apps act on behalf of your users, or when users sign in through another provider.