Web & Internet
Authentication Tokens (JWT)
O(n) to sign or verify a payload of length n — verifying costs exactly as much work as signing did.
The idea, in plain English
A JWT (JSON Web Token, said 'jot') is a signed, self-contained ticket that proves who you are. It's like a concert wristband with your seat number printed on it, plus a tamper-evident hologram sticker over the print. Anyone can read the seat number, but nobody can change it without visibly breaking the hologram. The 'seat number' part is your claims — who you are and your role. The 'hologram' part is a signature the server computes from a secret only it knows. Because the proof travels with the ticket itself, the server doesn't need to keep a guest list, called a session store, to check it. It just re-checks the hologram.
How it works
- 1The server builds a payload of plain claims about you, like your user ID and role.
- 2The server 'signs' that payload by running it through a formula together with a secret key it keeps private. This produces a signature.
- 3The server hands you a token: the payload plus its signature stuck together. No per-user record needs to be stored anywhere.
- 4On a later request, you send the whole token back. The server recomputes the signature from the payload using its secret and compares it to the one attached.
- 5If the freshly computed signature matches, the server trusts the payload's claims without looking anything up. If it doesn't match, the payload was tampered with, or someone guessed wrong, and the token is rejected.
When you'd use it
This applies to stateless APIs (Application Programming Interfaces) that don't want to store per-user session data, mobile app logins, and microservices that need to verify who's calling without sharing a session database between them.
Common beginner mistakes
- Don't assume a JWT is encrypted or secret. The payload part is normally just plain, readable text, so never put real secrets — passwords, credit card numbers — inside one. The signature only proves it wasn't altered, not that it's hidden from view.
- Don't read the payload without checking the signature. Skip that check, and anyone can hand-craft their own token claiming to be an admin, since nothing stopped them.
Try it — edit and run
Click the code to edit · press ⌘/Ctrl+↵ to run
Editable code. Tab and Shift+Tab indent. Press Escape, then Tab, to move focus out of the editor.
Issued token: 42:admin.sig2403
Verified user: 42 role: admin
Tampered token accepted: no
Wrong secret accepted: noNot sure this is the right topic? See the learning paths → or where this leads →