Skip to main content
Book 07 · SecurityPage 19 of 50

JWT

JSON Web Token

Pronunciation
jay-dub-ul-yoo-TEE or JOT
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/jwt

In short

A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.

What is a JWT?

A JSON Web Token is a string made of three Base64URL-encoded parts separated by dots: a header that names the signing algorithm, a payload containing claims such as sub (the user ID) and exp (the expiry time), and a signature. The signature is created with a secret or private key, so any change to the header or payload makes the token invalid.

In a typical login flow, the server issues a JWT after checking the user's credentials, and the client sends it back on later requests, usually in an Authorization: Bearer <token> header. The server verifies the signature and expiry and then trusts the claims without querying a session store, which makes JWTs popular for APIs, microservices, and single sign-on with OAuth and OpenID Connect.

A JWT is like a tamper-evident wristband at a festival: staff can check it at a glance without calling the ticket office, but anyone can read what is printed on it. The payload is only encoded, not encrypted, so never put passwords or other secrets inside it.

Compared with server-side sessions, JWTs are stateless, which makes them easy to scale but hard to revoke before they expire. Good practice is to keep access tokens short-lived, use refresh tokens to obtain new ones, always verify the signature against an explicit list of allowed algorithms, and store tokens where injected scripts cannot easily read them, such as HttpOnly cookies.

At a glance

A JWT is three Base64URL parts joined by dots: a header naming the signing algorithm, a payload holding claims such as sub and exp, and a signature computed from both with a secret.HeadereyJhbGciOi…"alg": "HS256","typ": "JWT"signing algorithmPayloadeyJzdWIiOi…"sub": "42","name": "Ada","exp": 1767225600claims: readable by anyoneSignatureSflKxwRJSM…HMAC-SHA256(header.payload,secret)proves nothing changed..
Anyone can decode the header and payload, so keep secrets out; the signature only proves that nothing was changed.

Key takeaways

  • A JWT has three parts: header, payload, and signature.
  • The signature proves the token has not been altered.
  • Anyone can read the payload, so it must not contain secrets.
  • JWTs are stateless and hard to revoke, so keep them short-lived.
  • Always verify the signature and restrict the allowed algorithms.

Example

Signing and verifying a JWT in Node.jsjavascript
import jwt from "jsonwebtoken";

const secret = process.env.JWT_SECRET;

// After a successful login: sign a short-lived token
const token = jwt.sign({ sub: user.id, role: "editor" }, secret, {
  expiresIn: "15m",
});

// On each request: check signature, algorithm, and expiry
// (throws an error if the token was altered or has expired)
const claims = jwt.verify(token, secret, { algorithms: ["HS256"] });
console.log(claims.sub);

Readers ask

What is the difference between JWT and session cookies?

With a session cookie, the server stores the session data and the cookie holds only a random ID that must be looked up. A JWT carries the user's claims inside the signed token itself, so no lookup is needed, but it is harder to revoke before it expires; a JWT can also be stored in a cookie, so the two are not mutually exclusive.

Is a JWT encrypted?

A standard signed JWT is not encrypted, and anyone can decode and read its payload. The signature only prevents tampering; encrypted tokens use a separate format called JWE.

Where should I store a JWT in the browser?

An HttpOnly, Secure cookie keeps the token out of reach of JavaScript, which protects it from theft through XSS, but then CSRF protection is needed. Storing it in localStorage avoids CSRF but exposes it to any script running on the page.

Often compared

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings