DEV Community

Cover image for šŸ” Understanding JWT (JSON Web Tokens)
Ankit chaurasiya
Ankit chaurasiya

Posted on

šŸ” Understanding JWT (JSON Web Tokens)

A Developer's Essential Guide What is JWT?

JSON Web Token (JWT) is a compact, URL-safe token format used for securely transmitting information between parties.

Think of it as a digital passport that carries user credentials and claims in a standardised, verifiable format.

šŸ”„ JWT Workflow:
1ļøāƒ£ Login Request → User provides credentials

2ļøāƒ£ JWT Issued → Server validates and responds with a token

3ļøāƒ£ Client Stores JWT → Usually in localStorage or sessionStorage

4ļøāƒ£ Authenticated Requests → JWT is sent in Authorisation: Bearer

5ļøāƒ£ Server Verifies & Responds

How is JWT Created?

A JWT consists of three parts separated by dots (.):

šŸ”¹ Header: Contains token type (JWT) and signing algorithm (e.g., HS256, RS256)

šŸ”¹ Payload: Contains claims (user data, permissions, expiration)

šŸ”¹ Signature: Ensures token integrity using a secret key or certificate

Structure: header.payload.signature

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFua2l0IiwiaWF0IjoxNjg4MDA2NDc1fQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Enter fullscreen mode Exit fullscreen mode

šŸ” JWT Payload Breakdown (Middle Part):

This is a Base64-encoded JSON and may look like this:

{ 
"sub": "1234567890", // Subject (user ID) 
"name": "Ankit", // User name 
"iat": 1688006475, // Issued At (timestamp)
"exp": 1688010075, // Expiration time (optional) 
"role": "admin" // Custom claim 
}
Enter fullscreen mode Exit fullscreen mode

Payload Information:
The payload contains "claims" - statements about the user and
additional data:
• Registered Claims: Standard fields like iss (issuer), exp (expiration), sub (subject)

• Public Claims: Custom fields defined in JWT registry

• Private Claims: Application-specific data like user roles, permissions

Key Benefits:

āœ… Stateless: No server-side session storage needed

āœ… Scalable: Perfect for micro services and distributed systems

āœ… Secure: Cryptographically signed and optionally encrypted

āœ… Cross-platform: Works across different domains and applications

Important Considerations:

āš ļø Size: JWTs can become large with extensive payload data

āš ļø Security: Never store sensitive data in payload (it's Base64 encoded, not encrypted)

āš ļø Expiration: Always set appropriate expiration times

āš ļø Storage: Store securely (httpOnly cookies preferred over localStorage)

Common Use Cases:

šŸŽÆ Authentication and authorization

šŸŽÆ Single Sign-On (SSO)

šŸŽÆ API security

šŸŽÆ Information exchange between services

Pro Tips: šŸ’” Use short expiration times with refresh tokens šŸ’” Implement proper token revocation strategies šŸ’” Always validate tokens on the server side applications?

Share your experiences below! šŸ‘‡

JWT #WebDevelopment #Authentication #Security #API #WebTokens #Programming

Top comments (0)