Inside a JWT: header, payload, and signature

Coming soon
FoundationalDifficulty: Foundational
DeveloperAudience: Developer
Security practitionerAudience: Security practitioner
Secure accessPurpose: Secure access

Wave 3 · Mechanisms · T03.01

Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

The question

What can be read from a JWT, and what does its signature prove?

What we will work through

Inspect a synthetic JWT and distinguish decoding from signature verification.

Before you begin

Previously covered: Authentication, authorization, and sessions: separate responsibilities.

Articles

Color theme

Language

Home