SECURITY / A CONCEPT NOTE

JWT

compact, self-contained tokens for passing identity and claims

~80 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

JSON Web Tokens (JWT) are base64-encoded JSON objects with a cryptographic signature. A JWT has three parts: header (algorithm), payload (claims like sub, exp, role), and signature. The server signs it with a secret or private key. Any service that trusts the public key can verify the token without contacting the issuer — no database lookup needed.

02 / FOLLOW THE MECHANISM

How a JWT is verified

  1. Auth server

    authenticates the user and issues a JWT: eyJhbGciOiJIUzI1NiIs... — signed with a secret key.

  2. Client

    stores the JWT (localStorage, cookie, or memory) and sends it as Authorization: Bearer <token> on every request.

  3. API server

    receives the request, extracts the JWT, and verifies the signature using the shared secret or public key.

  4. Server

    reads the claims from the payload — user_id: 42, role: admin, exp: 1719000000 — and grants or denies access.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

decode a JWT to inspect its payload

jwt-cli decode eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.dozjgNqP

EXAMPLE 02 · INCOMPLETE SKETCH

verify a JWT signature

jwt-cli verify --key "my-secret" eyJhbGciOiJIUzI1NiJ9...

The ellipsis omits required code or values. This sketch is not runnable as written.

Explore command anatomy in the CLI lab