JWT
JSON Web Token
- Pronunciation
- jay-dub-ul-yoo-TEE or JOT
In short
A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
What is a JWT?
A JSON Web Token is a string made of three Base64URL-encoded parts separated by dots: a header that names the signing algorithm, a payload containing claims such as sub (the user ID) and exp (the expiry time), and a signature. The signature is created with a secret or private key, so any change to the header or payload makes the token invalid.
In a typical login flow, the server issues a JWT after checking the user's credentials, and the client sends it back on later requests, usually in an Authorization: Bearer <token> header. The server verifies the signature and expiry and then trusts the claims without querying a session store, which makes JWTs popular for APIs, microservices, and single sign-on with OAuth and OpenID Connect.
A JWT is like a tamper-evident wristband at a festival: staff can check it at a glance without calling the ticket office, but anyone can read what is printed on it. The payload is only encoded, not encrypted, so never put passwords or other secrets inside it.
Compared with server-side sessions, JWTs are stateless, which makes them easy to scale but hard to revoke before they expire. Good practice is to keep access tokens short-lived, use refresh tokens to obtain new ones, always verify the signature against an explicit list of allowed algorithms, and store tokens where injected scripts cannot easily read them, such as HttpOnly cookies.
At a glance
Key takeaways
- A JWT has three parts: header, payload, and signature.
- The signature proves the token has not been altered.
- Anyone can read the payload, so it must not contain secrets.
- JWTs are stateless and hard to revoke, so keep them short-lived.
- Always verify the signature and restrict the allowed algorithms.
Example
import jwt from "jsonwebtoken";
const secret = process.env.JWT_SECRET;
// After a successful login: sign a short-lived token
const token = jwt.sign({ sub: user.id, role: "editor" }, secret, {
expiresIn: "15m",
});
// On each request: check signature, algorithm, and expiry
// (throws an error if the token was altered or has expired)
const claims = jwt.verify(token, secret, { algorithms: ["HS256"] });
console.log(claims.sub);Readers ask
What is the difference between JWT and session cookies?
With a session cookie, the server stores the session data and the cookie holds only a random ID that must be looked up. A JWT carries the user's claims inside the signed token itself, so no lookup is needed, but it is harder to revoke before it expires; a JWT can also be stored in a cookie, so the two are not mutually exclusive.
Is a JWT encrypted?
A standard signed JWT is not encrypted, and anyone can decode and read its payload. The signature only prevents tampering; encrypted tokens use a separate format called JWE.
Where should I store a JWT in the browser?
An HttpOnly, Secure cookie keeps the token out of reach of JavaScript, which protects it from theft through XSS, but then CSRF protection is needed. Storing it in localStorage avoids CSRF but exposes it to any script running on the page.
Often compared
- JWT vs SessionA JWT is a signed token that carries the user's identity, so servers verify it without a lookup, while sessions keep state on the server behind a random ID.
- JWT vs OAuthOAuth is a framework for giving an app limited access to user data; a JWT is a token format. They aren't rivals: OAuth often issues JWT access tokens.
See also
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- CookieWeb Development, p. 6A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
- JSONBackend & APIs, p. 25JSON is a lightweight, text-based format for storing and exchanging structured data as key-value pairs and lists, readable by both humans and machines.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- CSRFSecurity, p. 8CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- Refresh TokenSecurity, p. 33A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
- HMACSecurity, p. 15HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
- Base64Programming Fundamentals, p. 5Base64 is a way to write any binary data, such as an image or a key, using only 64 safe text characters, so it can pass through systems built for text.
Sources
Spotted a mistake or something missing on this page?Suggest an edit