# JWT (JSON Web Token)

URL: https://softwaredictionary.org/terms/jwt
Category: Security
Last updated: 2026-09-29
Pronunciation: jay-dub-ul-yoo-TEE or JOT

In short: A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.

## What is a JWT?

A JSON Web Token is a string made of three Base64URL-encoded parts separated by dots: a header that names the signing algorithm, a payload containing claims such as `sub` (the user ID) and `exp` (the expiry time), and a signature. The signature is created with a secret or private key, so any change to the header or payload makes the token invalid.

In a typical login flow, the server issues a JWT after checking the user's credentials, and the client sends it back on later requests, usually in an `Authorization: Bearer <token>` header. The server verifies the signature and expiry and then trusts the claims without querying a session store, which makes JWTs popular for APIs, microservices, and single sign-on with OAuth and OpenID Connect.

A JWT is like a tamper-evident wristband at a festival: staff can check it at a glance without calling the ticket office, but anyone can read what is printed on it. The payload is only encoded, not encrypted, so never put passwords or other secrets inside it.

Compared with server-side sessions, JWTs are stateless, which makes them easy to scale but hard to revoke before they expire. Good practice is to keep access tokens short-lived, use refresh tokens to obtain new ones, always verify the signature against an explicit list of allowed algorithms, and store tokens where injected scripts cannot easily read them, such as `HttpOnly` cookies.

## Key takeaways

- A JWT has three parts: header, payload, and signature.
- The signature proves the token has not been altered.
- Anyone can read the payload, so it must not contain secrets.
- JWTs are stateless and hard to revoke, so keep them short-lived.
- Always verify the signature and restrict the allowed algorithms.

## Example: Signing and verifying a JWT in Node.js

```javascript
import jwt from "jsonwebtoken";

const secret = process.env.JWT_SECRET;

// After a successful login: sign a short-lived token
const token = jwt.sign({ sub: user.id, role: "editor" }, secret, {
  expiresIn: "15m",
});

// On each request: check signature, algorithm, and expiry
// (throws an error if the token was altered or has expired)
const claims = jwt.verify(token, secret, { algorithms: ["HS256"] });
console.log(claims.sub);
```

## Frequently asked questions

**What is the difference between JWT and session cookies?**

With a session cookie, the server stores the session data and the cookie holds only a random ID that must be looked up. A JWT carries the user's claims inside the signed token itself, so no lookup is needed, but it is harder to revoke before it expires; a JWT can also be stored in a cookie, so the two are not mutually exclusive.

**Is a JWT encrypted?**

A standard signed JWT is not encrypted, and anyone can decode and read its payload. The signature only prevents tampering; encrypted tokens use a separate format called JWE.

**Where should I store a JWT in the browser?**

An `HttpOnly`, `Secure` cookie keeps the token out of reach of JavaScript, which protects it from theft through XSS, but then CSRF protection is needed. Storing it in `localStorage` avoids CSRF but exposes it to any script running on the page.

## Sources

- [RFC 7519: JSON Web Token (JWT)](https://www.rfc-editor.org/rfc/rfc7519.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
