JSON Web Token Introduction | Auth JWT
NEW:gettheJWTHandbookforfree[1]andlearnJWTsindepth!WhatisJSONWebToken?JSONWebToken(JWT)isanopenstandard(RFC7519[2])thatdefinesacompactandself-containedwayforsecurelytransmittinginformationbetweenpartiesasaJSONobject.Thisinformationcanbeverifiedandtrustedbecauseitisdigitallysigned.JWTscanbesignedusingasecret(withtheHMACalgorithm)orapublic/privatekeypairusingRSAorECDSA.AlthoughJWTscanbeencryptedtoalsoprovidesecrecybetweenparties,wewillfocusonsignedtokens.Signedtokenscanverifytheintegrityofthec...
NEW: get the JWT Handbook for free[1] and learn JWTs in depth!
What is JSON Web Token?JSON Web Token (JWT) is an open standard (RFC 7519[2]) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object. This information can be verified and trusted because it is digitally signed. JWTs can be signed using a secret (with the HMAC algorithm) or a public/private key pair using RSA or ECDSA.
Although JWTs can be encrypted to also provide secrecy between parties, we will focus on signed tokens. Signed tokens can verify the integrity of the claims contained within it, while encrypted tokens hide those claims from other parties. When tokens are signed using public/private key pairs, the signature also certifies that only the party holding the private key is the one that signed it.
When should you use JSON Web Tokens?Here are some scenarios where JSON Web Tokens are useful:
Authorization: This is the most c...