DEV Community

Discussion on: Understanding JWTs: A Simple Guide for Beginners

Collapse
 
thib3113 profile image
Thibaut SEVERAC

Not always ... The problem here is : "jwt is an abstract" . You will never create a jwt .

You will create a jws or a jwe .
Jws is a signed jwt, the one presented here, no security about reading the body .

Jwe is an encrypted jwt, you can't read it without the private key .

Jws can be useful because you can read the expiration, or validate the signature with a jwks .. but the content is readable

Collapse
 
arial profile image
arial

Oh cool, I was just using jwt.io as my source so I guess that's a jws implementation.