SECURITY / A CONCEPT NOTE
JWT
compact, self-contained tokens for passing identity and claims
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
JSON Web Tokens (JWT) are base64-encoded JSON objects with a cryptographic signature. A JWT has three parts: header (algorithm), payload (claims like sub, exp, role), and signature. The server signs it with a secret or private key. Any service that trusts the public key can verify the token without contacting the issuer — no database lookup needed.
02 / FOLLOW THE MECHANISM
How a JWT is verified
Auth server
authenticates the user and issues a JWT:
eyJhbGciOiJIUzI1NiIs...— signed with a secret key.Client
stores the JWT (localStorage, cookie, or memory) and sends it as
Authorization: Bearer <token>on every request.API server
receives the request, extracts the JWT, and verifies the signature using the shared secret or public key.
Server
reads the claims from the payload —
user_id: 42,role: admin,exp: 1719000000— and grants or denies access.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
decode a JWT to inspect its payload
jwt-cli decode eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.dozjgNqPverify a JWT signature
jwt-cli verify --key "my-secret" eyJhbGciOiJIUzI1NiJ9...The ellipsis omits required code or values. This sketch is not runnable as written.
05 / CHECK YOURSELF
Could you explain JWT to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityWAFfiltering malicious traffic before it reaches your application