Skip to main content

JSON Web Tokens


JSON Web Tokens (JWTs) are digitally signed JSON objects based on the open standard RFC 7519. These tokens provide a compact, self-contained method for securely transmitting information between parties. Tokens are signed with an RSA-encoded public/private key pair. The signature is calculated using the header and body, which enables the receiver to validate that the content has not been tampered with.

A JWT takes the form of a string consisting of three parts separated by dots:

<Header>.<Payload>.<Signature>

The header and payload are Base64-encoded JSON and contain these claims:

Header: the algorithm and token type. For example:

{  "kid": "zu",  "alg": "RS256"}

Payload: the claims of what the token represents. For example:

{  "sub": "1234567890",  "name": "John Doe",  "iat": 1516239022}

Signature: computed from the header and payload using a secret or private key.

Last published: September 29, 2026