Skip to main content

Side by side

JWTvsOAuth

What is the difference between JWT and OAuth?

Updated 3 min read7 differences

In short

OAuth is a framework for giving an app limited access to user data; a JWT is a token format. They aren't rivals: OAuth often issues JWT access tokens.

JWT

JSON Web Token

A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.

Read the page on JWT

OAuth

OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.

Read the page on OAuth

JWT and OAuth compared

AspectJWTOAuth
What it isA token formatAn authorization framework: a set of flows
AnswersWhat a token says, and whether it was changedHow an app gets permission to call an API for a user
Defined inRFC 7519RFC 6749 (OAuth 2.0)
Made ofA header, claims such as subject and expiry, and a signatureRoles: client, user, authorization server, resource server
Used forAccess tokens, ID tokens and session tokensDelegated access, such as an app reading your calendar
Works without the other?Yes, wherever signed tokens are neededYes, with opaque tokens checked by the server
Common mistakeDecoding without verifying the signatureUsing it as a login protocol on its own

The difference, explained

A JSON Web Token (JWT) is a format: a signed string carrying claims, such as who the user is and when the token expires. OAuth 2.0 is an authorization framework: a set of flows by which an app gets the user's permission to call an API on their behalf, without ever seeing their password.

They meet where OAuth hands out tokens. After the user approves an app, the authorization server issues an access token, and the API accepts it with each request. OAuth doesn't say what that token looks like: it can be a random string the API checks with the server, or a JWT the API verifies by itself from its signature. Many providers choose JWTs for that reason, and OpenID Connect, built on OAuth, always uses a JWT for its ID token.

So asking JWT or OAuth is like asking passport or border control: one is a document, the other is the process that decides who gets one and what it allows. You can use JWTs without OAuth, for example as the session tokens of your own login, and OAuth without JWTs, with opaque tokens.

Two mistakes are common. The first is treating OAuth as login: OAuth answers what an app may do, not who the user is, and signing users in with another provider is done with OpenID Connect on top of OAuth. The second is trusting a JWT without checking its signature, issuer, audience and expiry: decoding a token is not verifying it.

Which one should you use?

Choose JWT when…

  • Services need to verify a token on their own, without calling a central server.
  • You are deciding what goes inside a token and how it is signed.
  • You need a compact, signed way to pass identity between your own services.

Choose OAuth when…

  • A third-party app needs limited access to a user's data in your service.
  • Users should grant and revoke permissions without sharing a password.
  • You want standard flows that existing clients and libraries already support.

Verifying a JWT vs starting an OAuth flow

JWTjavascript
// JWT: decoding shows the claims, verifying proves they are genuine
import { jwtVerify } from "jose";

const { payload } = await jwtVerify(token, publicKey, {
  issuer: "https://auth.example.com",
  audience: "orders-api",
});
console.log(payload.sub, payload.scope); // who, and what they may do
OAuthjavascript
// OAuth: send the user to approve, then swap the code for tokens
const url = new URL("https://auth.example.com/authorize");
url.search = new URLSearchParams({
  response_type: "code",
  client_id: CLIENT_ID,
  redirect_uri: "https://app.example.com/callback",
  scope: "orders:read",
  state,
  code_challenge,               // PKCE
  code_challenge_method: "S256",
});
location.href = url; // the user signs in and approves on the provider's page

Readers ask

Is OAuth the same as OpenID Connect?

No. OpenID Connect is a layer on top of OAuth 2.0 that adds login: an ID token, which is a JWT, tells the app who the user is.

Are OAuth access tokens always JWTs?

No. The specification leaves the format open. Some providers issue JWTs that APIs can verify locally; others issue opaque strings that the API checks with the authorization server, which makes revoking them easier.

Do I need OAuth for my own app's login?

Not necessarily. When your own users sign in to your own app, a session or a token you issue yourself is enough. OAuth matters when other apps act on behalf of your users, or when users sign in through another provider.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings