What is a JSON Web Token (JWT)?
An open standard (RFC 7519) securely representing authentication claims between two parties in a compact, URL-safe, digitally signed format.
Micro-Technology Solutions
Paste, decode, audit, verify and even generate JSON Web Tokens — without them ever leaving your browser.
Base64Url structure, standard claims, signature algorithms, and stateless security.
A JWT comprises three dot-separated Base64Url parts: Header (algorithm metadata), Payload (user claims), and Signature (cryptographic tamper-proof proof).
HMAC relies on a shared symmetric secret. Microservices favor asymmetric RS256/ES256 where an Auth Server signs with a private key and consumers verify with public keys.
RFC 7519 establishes UNIX epoch timestamps for `exp` (expiration), `iat` (issued at), and `nbf` (not before), alongside `iss` (issuer) and `aud` (audience).
Access Tokens should have short lifespans (5-15 mins). Long-term session continuity is handled via opaque Refresh Tokens stored in secure `HttpOnly` cookies.
Step-by-step fixes for expired tokens, signature mismatches, and algorithm exploits.
Official 'jot' pronunciation, the 4KB header limit, and the stateless revocation paradox.
Section 1 of RFC 7519 explicitly specifies: 'The suggested pronunciation of JWT is the same as the English word *jot*'.
Servers like Nginx enforce 4KB-8KB request header limits. Overloading JWT payloads triggers HTTP `431 Request Header Fields Too Large` errors.
Because JWT verification is stateless without database roundtrips, valid signatures remain valid until `exp`. Early revocation requires stateful blacklists like Redis.
JWT belongs to the IETF JOSE suite alongside JWS (signatures), JWE (encryption), JWK (key representations), and JWA (algorithms).
Learn the fundamental concepts, protocols, and technical terminology of this tool.
An open standard (RFC 7519) securely representing authentication claims between two parties in a compact, URL-safe, digitally signed format.
Key-value statements inside the token payload payload expressing identity attributes, roles, and administrative metadata (e.g., `sub`, `exp`, `iss`).
A cryptographic hash calculated over header and payload strings using a shared secret or private key, preventing data tampering in transit.
A Unix epoch timestamp defining the exact second after which the authentication token must be rejected by backend API resource servers.