JWT
In depthProtocol / format
Also known as: JSON Web Token
Compact, self-contained token for authentication, carrying cryptographically signed claims.
JWT, explained
Written by EduVerseWhat it is
A JWT (JSON Web Token) is a compact token, usually made of three Base64URL-encoded parts separated by dots: a header, a payload with claims such as the user id and expiry time, and a signature. The server signs it with a secret or private key, so any change to the contents makes the signature invalid.
Why teams use it
After login, the server issues a token that the client sends with every request, usually in an Authorization: Bearer header. Checking the signature is enough, so no session lookup is needed, which suits APIs spread across several services. The catch: a JWT is signed, not encrypted, and hard to revoke before it expires.
An example from work
Your API suddenly returns 401 Unauthorized after you’ve been logged in for an hour. You copy the token from the Authorization header in DevTools, paste it into a decoder such as jwt.io, and see that the exp claim lies in the past. The token simply expired, and your frontend never asked for a new one.
Our own explanation, not a quote from the book.
In the book
Sentences from The Software Realm, Decoded that mention JWT, exactly as printed.
6 more passages about JWT in the full book
Read every conversation where JWT comes up, with the interactive slides and demos.
Where it fits
Stateless API authentication, single sign-on
Coverage in the book
Covered in depth: multiple pages with explanations, examples and simulations.