# JWT

> JSON Web Token — a signed, self-contained credential a server can verify without a database lookup; the standard way APIs say 'this request is you'.

A JWT is three base64 blobs: header, claims, signature. The server signs 'user 42, role admin, expires 15:00' and later verifies the signature to trust the claims — no session table needed. That is the appeal for APIs and microservices: verification is local and cheap.

The footguns are known: the token is readable by anyone who holds it, so sensitive data does not belong in it; 'none' algorithm acceptance and weak secrets are classic breaks; and a stolen JWT is a valid credential until expiry, which is why tokens are kept short-lived with refresh, not long-lived and revocable.

## Related terms

- https://dfieldsolutions.com/en/glossary/oauth.md
- https://dfieldsolutions.com/en/glossary/session-hijacking.md
- https://dfieldsolutions.com/en/glossary/least-privilege.md

---

Source: https://dfieldsolutions.com/en/glossary/jwt
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
