JWT: what is it
Tokens, authorization in the API, refresh tokens, where to store JWT on the client.
JWT (JSON Web Token) is a compact, self-contained way to securely transmit information between parties as a JSON object. Used for authentication and authorization in web applications.
What is JWT
A JWT consists of three Base64URL-encoded parts separated by dots: header.payload.signature
- Header — algorithm and token type:
{"alg":"HS256","typ":"JWT"} - Payload — claims: user ID, roles, expiration time
- Signature — HMAC-SHA256 or RSA of header + payload + secret key
Signature algorithms
- User logs in (username/password)
- Server creates JWT with user data and signs it
- Client stores JWT (localStorage or httpOnly cookie)
- Client sends JWT in
Authorization: Bearer <token>header - Server verifies signature and reads user data from payload
OAuth 2.0
sub— subject (user ID)iat— issued at (Unix timestamp)exp— expiration timeiss— issueraud— audiencejti— JWT ID (for revocation)
JWT vs OAuth 2.0
⚠️ Never store sensitive data in payload — it's Base64 encoded, not encrypted. Anyone can decode it. Use HTTPS always. Short expiration times (15 min access token + 7 day refresh token). Store in httpOnly cookies to prevent XSS.
Related Tools
- Developer Tools — JWT decoder built-in
- SSL Check — secure your API endpoint