Skip to content
EduVerse

JWT

In depth

Protocol / format

Also known as: JSON Web Token

Compact, self-contained token for authentication, carrying cryptographically signed claims.

JWT, explained

Written by EduVerse

What it is

A JWT (JSON Web Token) is a compact token, usually made of three Base64URL-encoded parts separated by dots: a header, a payload with claims such as the user id and expiry time, and a signature. The server signs it with a secret or private key, so any change to the contents makes the signature invalid.

Why teams use it

After login, the server issues a token that the client sends with every request, usually in an Authorization: Bearer header. Checking the signature is enough, so no session lookup is needed, which suits APIs spread across several services. The catch: a JWT is signed, not encrypted, and hard to revoke before it expires.

An example from work

Your API suddenly returns 401 Unauthorized after you’ve been logged in for an hour. You copy the token from the Authorization header in DevTools, paste it into a decoder such as jwt.io, and see that the exp claim lies in the past. The token simply expired, and your frontend never asked for a new one.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention JWT, exactly as printed.

    6 more passages about JWT in the full book

    Read every conversation where JWT comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Stateless API authentication, single sign-on

    Coverage in the book

    In depth

    Covered in depth: multiple pages with explanations, examples and simulations.

    Appears in