DFIELDSOLUTIONS

Security

GlossaryJWT

JSON Web Token — a signed, self-contained credential a server can verify without a database lookup; the standard way APIs say 'this request is you'.

A JWT is three base64 blobs: header, claims, signature. The server signs 'user 42, role admin, expires 15:00' and later verifies the signature to trust the claims — no session table needed. That is the appeal for APIs and microservices: verification is local and cheap.

The footguns are known: the token is readable by anyone who holds it, so sensitive data does not belong in it; 'none' algorithm acceptance and weak secrets are classic breaks; and a stolen JWT is a valid credential until expiry, which is why tokens are kept short-lived with refresh, not long-lived and revocable.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain