Taking Apart a JWT

JWTs show up everywhere in modern applications. But what is all that encoded text, what does it contain, and what happens when an API receives it?

Before we take it apart

What is a token?

When you sign in to an application, it needs a way to know who you are and what you're allowed to do.

You sign in
token
Your app

A token carries information between systems. A JWT (JSON Web Token) packages some of that information into a compact string that applications can pass around and verify.

What's inside the token?

Let's take one apart.

click the token to see it's parts ↓
now let's use it ↓
Your app GET /photos/42
token
Photos API waiting...

checking the token...

✓ signature
✓ audience
✓ expiration
✓ scope
✓

The token checks out.

The API knows who the token is for, that it hasn't expired, and that it has the permission it needs.

but what happens when one of those things is wrong? part two coming soon...