JSON Web Tokens
JSON Web Tokens (JWTs) are digitally signed JSON objects based on the open standard RFC 7519. These tokens provide a compact, self-contained method for securely transmitting information between parties. These tokens are signed with an RSA (Rivest-Shamir-Adleman)-encoded public/private key pair. The signature is calculated using the header and body, which enables the receiver to validate that the content has not been tampered with.
A JWT takes the form of a string, and consists of three parts separated by dots:
<Header>.<Payload>.<Signature>The header and payload is Base64-encoded JSON and contains these claims:
Header: the algorithm and token type. For example:
{ "kid": "00SvIaGIfyaw897rDeG9eFdODKaCKc1q", "alg": "RS256"}Payload: the claims of what the token represents. For example:
{ "sub": "1234567890", "name": "John Doe", "iat": 1516239022}Signature: computed from the header and payload using a secret or private key.
Thanks for your feedback!
Last published: September 29, 2026