Skip to content
José da Cruz

Enterprise Architect, and Life Thinker

José da Cruz

Enterprise Architect, and Life Thinker

JSON Web Token (JWT)

josedacruz, July 12, 2023

JSON Web Token (JWT)

is an open standard that defines a compact and self-contained way for securely transmitting information between parties as a JSON object.

  • A server issues a token to a client after verifying its credentials (ex: username and password).
  • The client then uses the token to access the protected resources on the server.
  • Is composed of three parts: a header, a payload, and a signature.
  • Header: contains metadata. Algorithm used to sign the token.
  • Payload: contains the claims and the data.
  • Signature: used to verify the integrity and authenticity of the token
  • The server verifies the token by:
  • checking its signature, validating the claims (identity, roles, permissions, expiration time)
  • The token is not necessary to be stored (it is signed).

Related

architecture authenticationauthorizationjsonwebtokenjwtsecurity

Post navigation

Previous post
Next post

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • architecture (154)
  • artificial-intelligence (6)
  • books (2)
  • courses (4)
  • decision-frameworks (4)
  • finances (1)
  • java (8)
  • life-improvement (20)
  • metrics (3)
  • observability (2)
  • puzzles and challenges (3)
  • reviews (1)
  • security (8)
  • spring-boot (36)
  • Systems Thinking (3)
  • GitHub Weekly: MCP Tools Trending Right Now (September 28 – October 4, 2026)
  • The Bulkhead Pattern: Why One Slow Dependency Shouldn’t Sink the Whole Ship
  • Essential Reading: A Philosophy of Software Design — Fighting Complexity One Module at a Time
  • GitHub Weekly: Top 10 Trending Repos (September 21 – September 27, 2026)
  • The Volunteer Tax: Why Raising Your Hand in a Meeting Makes You the Permanent Owner
©2026 José da Cruz | WordPress Theme by SuperbThemes