Taking Apart a JWT
JWTs show up everywhere in modern applications. But what is all that encoded text, what does it contain, and what happens when an API receives it?
What is a token?
When you sign in to an application, it needs a way to know who you are and what you're allowed to do.
A token carries information between systems. A JWT (JSON Web Token) packages some of that information into a compact string that applications can pass around and verify.
What's inside the token?
Let's take one apart.
GET /photos/42
checking the token...
The token checks out.
The API knows who the token is for, that it hasn't expired, and that it has the permission it needs.