JWT (JSON Web Token) is a compact, self-contained way to securely transmit information between parties as a JSON object. Used for authentication and authorization in web applications.

What is JWT

A JWT consists of three Base64URL-encoded parts separated by dots: header.payload.signature

Signature algorithms

  1. User logs in (username/password)
  2. Server creates JWT with user data and signs it
  3. Client stores JWT (localStorage or httpOnly cookie)
  4. Client sends JWT in Authorization: Bearer <token> header
  5. Server verifies signature and reads user data from payload

OAuth 2.0

JWT vs OAuth 2.0

⚠️ Never store sensitive data in payload — it's Base64 encoded, not encrypted. Anyone can decode it. Use HTTPS always. Short expiration times (15 min access token + 7 day refresh token). Store in httpOnly cookies to prevent XSS.

Related Tools

🔧 JWT Decoder →