A JWT is three base64 blobs: header, claims, signature. The server signs 'user 42, role admin, expires 15:00' and later verifies the signature to trust the claims — no session table needed. That is the appeal for APIs and microservices: verification is local and cheap.
The footguns are known: the token is readable by anyone who holds it, so sensitive data does not belong in it; 'none' algorithm acceptance and weak secrets are classic breaks; and a stolen JWT is a valid credential until expiry, which is why tokens are kept short-lived with refresh, not long-lived and revocable.
Related terms
OAuth
The authorization protocol behind 'Sign in with Google' — lets a service act on your behalf with a scoped token instead of your password.
Session hijacking
Stealing the token that proves a logged-in session — whoever holds it is you, no password needed.
Least privilege
Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
