# jwt

Source: https://startwithidentity.com/glossary/jwt/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

A compact, URL-safe token format with three base64-encoded segments: header, payload, and signature. Defined by RFC 7519. JWTs are the dominant format for ID tokens and bearer access tokens. Verify the signature; never trust unsigned JWTs.

JWTs are easy to produce and easy to verify wrongly, which is why they generate a steady stream of authentication bypasses: accepting `alg: none`, confusing HMAC and RSA verification, skipping the audience check, or trusting a `kid` that points at attacker-controlled key material. Use a maintained library, pin the expected algorithms, and validate issuer, audience, and expiry every time. A JWT is signed, not encrypted, so nothing secret belongs in the payload.

See also: [claims](https://startwithidentity.com/glossary/claims/), [JWKS](https://startwithidentity.com/glossary/jwks/), [access token](https://startwithidentity.com/glossary/access-token/), [identity CVE catalog](https://startwithidentity.com/cves/)
