Skip to main content

JSON Web Tokens


JSON Web Tokens (JWTs) are digitally signed JSON objects based on the open standard RFC 7519. These tokens provide a compact, self-contained method for securely transmitting information between parties. These tokens are signed with an RSA (Rivest-Shamir-Adleman)-encoded public/private key pair. The signature is calculated using the header and body, which enables the receiver to validate that the content has not been tampered with.

A JWT takes the form of a string, and consists of three parts separated by dots:

<Header>.<Payload>.<Signature>

The header and payload is Base64-encoded JSON and contains these claims:

Header: the algorithm and token type. For example:

{  "kid": "00SvIaGIfyaw897rDeG9eFdODKaCKc1q",  "alg": "RS256"}

Payload: the claims of what the token represents. For example:

{  "sub": "1234567890",  "name": "John Doe",  "iat": 1516239022}

Signature: computed from the header and payload using a secret or private key.

Last published: September 29, 2026