<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>JSON Web Token</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/JSON_Web_Token"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-JSON_Web_Token rootpage-JSON_Web_Token skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">JSON Web Token</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p class="mw-empty-elt">
</p>
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox hproduct"><caption class="infobox-title fn">JSON Web Token</caption><tbody><tr><th scope="row" class="infobox-label">Abbreviation</th><td class="infobox-data">JWT</td></tr><tr><th scope="row" class="infobox-label">Status</th><td class="infobox-data"><a href="Internet_Standard#Proposed_Standard" title="Internet Standard">Proposed Standard</a></td></tr><tr><th scope="row" class="infobox-label">First published</th><td class="infobox-data">December 28, 2010<span style="display: none;"> (<span class="bday dtstart published updated itvstart">2010-12-28</span>)</span></td></tr><tr><th scope="row" class="infobox-label">Latest version</th><td class="infobox-data"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7519">7519</a><br>May 2015</td></tr><tr><th scope="row" class="infobox-label">Organization</th><td class="infobox-data"><a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">IETF</a></td></tr><tr><th scope="row" class="infobox-label">Committee</th><td class="infobox-data"><a href="Internet_Engineering_Task_Force#Internet_Engineering_Steering_Group" title="Internet Engineering Task Force">IEGS</a></td></tr><tr><th scope="row" class="infobox-label">Authors</th><td class="infobox-data"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */
.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}
/* end https://en.wikipedia.org/ */
</style><div class="plainlist">
<ul><li>Michael B. Jones</li>
<li><a href="Microsoft" title="Microsoft">Microsoft</a></li>
<li>John Bradley</li>
<li><a href="Ping_Identity" title="Ping Identity">Ping Identity</a></li>
<li>Nat Sakimura</li>
<li><a href="Nomura_Research_Institute" title="Nomura Research Institute">NRI</a></li></ul>
</div></td></tr><tr><th scope="row" class="infobox-label">Base standards</th><td class="infobox-data"><div class="plainlist">
<ul><li><a href="JSON" title="JSON">JSON</a></li>
<li><a href="JSON_Web_Encryption" title="JSON Web Encryption">JSON Web Encryption</a> (JWE)</li>
<li><a href="JSON_Web_Signature" title="JSON Web Signature">JSON Web Signature</a> (JWS)</li></ul>
</div></td></tr><tr><th scope="row" class="infobox-label">Domain</th><td class="infobox-data"><a href="Data_exchange" title="Data exchange">Data exchange</a></td></tr><tr><th scope="row" class="infobox-label">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7519">datatracker<wbr>.ietf<wbr>.org<wbr>/doc<wbr>/html<wbr>/rfc7519</a></span></td></tr></tbody></table>
<p><b>JSON Web Token</b> (<b>JWT</b>, suggested pronunciation <span class="rt-commentedText nowrap"><span class="IPA nopopups noexcerpt" lang="en-fonipa">/<span style="border-bottom:1px dotted"><span title="/dʒ/: 'j' in 'jam'">dʒ</span><span title="/ɒ/: 'o' in 'body'">ɒ</span><span title="'t' in 'tie'">t</span></span>/</span></span>, same as the word "jot"<sup id="cite_ref-rfc7519_1-0" class="reference"><a href="#cite_note-rfc7519-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>) is a <a href="Internet_Standard#Proposed_Standard" title="Internet Standard">proposed Internet standard</a> for creating data with optional <a href="Signature_(cryptography)" class="mw-redirect" title="Signature (cryptography)">signature</a> and/or optional <a href="Encryption" title="Encryption">encryption</a> whose <a href="Payload_(computing)" title="Payload (computing)">payload</a> holds <a href="JSON" title="JSON">JSON</a> that asserts some number of <a href="Claims-based_identity" title="Claims-based identity">claims</a>. The tokens are signed either using a <a href="Shared_secret" title="Shared secret">private secret</a> or a <a href="Public-key_cryptography" title="Public-key cryptography">public/private key</a>.
</p><p>For example, a server could generate a token that has the claim "logged in as administrator" and provide that to a client. The client could then use that token to prove that it is logged in as admin. The tokens can be signed by one party's private key (usually the server's) so that any party can subsequently verify whether the token is legitimate. If the other party, by some suitable and trustworthy means, is in possession of the corresponding public key, they too are able to verify the token's legitimacy. The <a href="Session_token" class="mw-redirect" title="Session token">tokens</a> are designed to be compact,<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> <a href="URL" title="URL">URL</a>-safe,<sup id="cite_ref-jwtintro_3-0" class="reference"><a href="#cite_note-jwtintro-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> and usable, especially in a <a href="Web_browser" title="Web browser">web-browser</a> <a href="Single_sign-on" title="Single sign-on">single-sign-on</a> (SSO) context. JWT claims can typically be used to pass identity of authenticated users between an <a href="Identity_provider" title="Identity provider">identity provider</a> and a <a href="Service_provider" title="Service provider">service provider</a>, or any other type of claims as required by business processes.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>JWT relies on other JSON-based standards: <a href="JSON_Web_Signature" title="JSON Web Signature">JSON Web Signature</a> and <a href="JSON_Web_Encryption" title="JSON Web Encryption">JSON Web Encryption</a>.<sup id="cite_ref-rfc7519_1-1" class="reference"><a href="#cite_note-rfc7519-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:1_6-0" class="reference"><a href="#cite_note-:1-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:2_7-0" class="reference"><a href="#cite_note-:2-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Structure">Structure</h2></div>
<dl><dt>Header</dt>
<dd>Identifies which algorithm is used to generate the signature. In the below example, <code>HS256</code> indicates that this token is signed using HMAC-SHA256.</dd></dl>
<dl><dd>Typical cryptographic algorithms used are <a href="HMAC" title="HMAC">HMAC</a> with <a href="SHA-256" class="mw-redirect" title="SHA-256">SHA-256</a> (HS256) and <a href="Digital_signature" title="Digital signature">RSA signature</a> with SHA-256 (RS256). JWA (JSON Web Algorithms) RFC 7518 introduces many more for both authentication and encryption.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup></dd>
<dd><div class="mw-highlight mw-highlight-lang-json mw-content-ltr" dir="ltr"><pre><span class="p">{</span>
<span class="w"> </span><span class="nt">"alg"</span><span class="p">:</span><span class="w"> </span><span class="s2">"HS256"</span><span class="p">,</span>
<span class="w"> </span><span class="nt">"typ"</span><span class="p">:</span><span class="w"> </span><span class="s2">"JWT"</span>
<span class="p">}</span>
</pre></div></dd>
<dt>Payload</dt>
<dd>Contains a set of claims. The JWT specification defines seven Registered Claim Names, which are the <a href="#Standard_fields">standard fields</a> commonly included in tokens.<sup id="cite_ref-rfc7519_1-2" class="reference"><a href="#cite_note-rfc7519-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> Custom claims are usually also included, depending on the purpose of the token.</dd>
<dd>This example has the standard Issued At Time claim (<code>iat</code>) and a custom claim (<code>loggedInAs</code>).</dd>
<dd><div class="mw-highlight mw-highlight-lang-json mw-content-ltr" dir="ltr"><pre><span class="p">{</span>
<span class="w"> </span><span class="nt">"loggedInAs"</span><span class="p">:</span><span class="w"> </span><span class="s2">"admin"</span><span class="p">,</span>
<span class="w"> </span><span class="nt">"iat"</span><span class="p">:</span><span class="w"> </span><span class="mi">1422779638</span>
<span class="p">}</span>
</pre></div></dd>
<dt>Signature</dt>
<dd>Securely validates the token. The signature is calculated by encoding the header and payload using <a href="Base64#URL_applications" title="Base64">Base64url Encoding</a> <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4648">4648</a> and concatenating the two together with a period separator. That string is then run through the cryptographic algorithm specified in the header. This example uses HMAC-SHA256 with a shared secret (public key algorithms are also defined). The <i>Base64url Encoding</i> is similar to <a href="Base64" title="Base64">base64</a>, but uses different non-alphanumeric characters and omits padding.</dd>
<dd><div class="mw-highlight mw-highlight-lang-javascript mw-content-ltr" dir="ltr"><pre><span class="nx">HMAC_SHA256</span><span class="p">(</span>
<span class="w"> </span><span class="nx">secret</span><span class="p">,</span>
<span class="w"> </span><span class="nx">base64urlEncoding</span><span class="p">(</span><span class="nx">header</span><span class="p">)</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="s1">'.'</span><span class="w"> </span><span class="o">+</span>
<span class="w"> </span><span class="nx">base64urlEncoding</span><span class="p">(</span><span class="nx">payload</span><span class="p">)</span>
<span class="p">)</span>
</pre></div></dd></dl>
<p>The three are encoded separately using <a href="Base64#URL_applications" title="Base64">Base64url Encoding</a> <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4648">4648</a>, and concatenated using periods to produce the JWT:
</p>
<div class="mw-highlight mw-highlight-lang-javascript mw-content-ltr" dir="ltr"><pre><span class="kd">const</span><span class="w"> </span><span class="nx">token</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nx">base64urlEncoding</span><span class="p">(</span><span class="nx">header</span><span class="p">)</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="s1">'.'</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="nx">base64urlEncoding</span><span class="p">(</span><span class="nx">payload</span><span class="p">)</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="s1">'.'</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="nx">base64urlEncoding</span><span class="p">(</span><span class="nx">signature</span><span class="p">)</span>
</pre></div>
<p>The above data and the secret of "secretkey" creates the token:
</p><p><code>eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJsb2dnZWRJbkFzIjoiYWRtaW4iLCJpYXQiOjE0MjI3Nzk2Mzh9.gzSraSYS8EXBxLN
_oWnFSRgCzcmJmMjLiuyu5CSpyHI=</code>
</p><p><i>(The above json strings are formatted without newlines or spaces, into utf-8 byte arrays. This is important as even slight changes in the data will affect the resulting token)</i>
</p><p>This resulting token can be easily passed into <a href="HTML" title="HTML">HTML</a> and <a href="HTTP" title="HTTP">HTTP</a>.<sup id="cite_ref-jwtintro_3-1" class="reference"><a href="#cite_note-jwtintro-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Use">Use</h2></div><p>
In authentication, when a user successfully logs in, a JSON Web Token (JWT) is often returned. This token should be sent to the client using a secure mechanism like an <a href="HTTP_cookie#Secure_and_HttpOnly" title="HTTP cookie">HTTP-only cookie</a>. Storing the JWT locally in browser storage mechanisms like <a href="Web_storage" title="Web storage">local or session storage</a> is discouraged. This is because JavaScript running on the client-side (including browser extensions) can access these storage mechanisms, exposing the JWT and compromising security. For unattended processes, the client may also authenticate directly by generating and signing its own JWT with a pre-shared secret and pass it to a <a href="OAuth" title="OAuth">OAuth</a> compliant service like so:</p><div class="mw-highlight mw-highlight-lang-mime mw-content-ltr" dir="ltr"><pre><span class="err">POST /oauth2/token</span>
<span class="nt">Content-type:</span><span class="w"> </span><span class="nl">application</span><span class="dl">/</span><span class="nl">x-www-form-urlencoded</span>
<span class="nt">grant_type</span><span class="o">=</span><span class="s">urn:ietf:params:oauth:grant-type:jwt-bearer</span><span class="p">&</span><span class="nt">assertion</span><span class="o">=</span><span class="s">eyJhb...</span>
</pre></div><p>If the client passes a valid JWT assertion the server will generate an access_token valid for making calls to the application and pass it back to the client:</p><div class="mw-highlight mw-highlight-lang-json mw-content-ltr" dir="ltr"><pre><span class="p">{</span>
<span class="w"> </span><span class="nt">"access_token"</span><span class="p">:</span><span class="w"> </span><span class="s2">"eyJhb..."</span><span class="p">,</span>
<span class="w"> </span><span class="nt">"token_type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Bearer"</span><span class="p">,</span>
<span class="w"> </span><span class="nt">"expires_in"</span><span class="p">:</span><span class="w"> </span><span class="mi">3600</span>
<span class="p">}</span>
</pre></div><p>When the client wants to access a protected route or resource, the user agent should send the JWT, typically in the <code>Authorization</code> <a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP header</a> using the <code>Bearer</code> schema. The content of the header might look like the following:
</p><pre>Authorization: Bearer eyJhbGci<i>...<snip>...</i>yu5CSpyHI
</pre>
<p>This is a stateless authentication mechanism as the user state is never saved in server memory. The server's protected routes will check for a valid JWT in the Authorization header, and if it is present, the user will be allowed to access protected resources. As JWTs are self-contained, all the necessary information is there, reducing the need to query the database multiple times.
</p>
<div class="mw-heading mw-heading2"><h2 id="Standard_fields">Standard fields</h2></div>
<table class="wikitable">
<tbody><tr>
<th>Code
</th>
<th>Name
</th>
<th>Description
</th></tr>
<tr>
<th colspan="2" style="background: #ececec; color: black; font-weight: bold; vertical-align: middle; text-align: left;" class="table-rh">Standard claim fields
</th>
<td>The internet drafts define the following standard fields ("claims") that can be used inside a JWT claim set.
</td></tr>
<tr>
<td><code>iss</code>
</td>
<td>Issuer
</td>
<td>Identifies principal that issued the JWT.
</td></tr>
<tr>
<td><code>sub</code>
</td>
<td>Subject
</td>
<td>Identifies the subject of the JWT.
</td></tr>
<tr>
<td><code>aud</code>
</td>
<td>Audience
</td>
<td>Identifies the recipients that the JWT is intended for. Each principal intended to process the JWT <b>must</b> identify itself with a value in the audience claim. If the principal processing the claim does not identify itself with a value in the <code>aud</code> claim when this claim is present, then the JWT <b>must</b> be rejected.
</td></tr>
<tr>
<td><code>exp</code>
</td>
<td>Expiration Time
</td>
<td>Identifies the expiration time on and after which the JWT <b>must not</b> be accepted for processing. The value must be a NumericDate:<sup id="cite_ref-rfc-7519-section-4.1.4_9-0" class="reference"><a href="#cite_note-rfc-7519-section-4.1.4-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> either an integer or decimal, representing seconds past <a href="Unix_time" title="Unix time">1970-01-01 00:00:00Z</a>.
</td></tr>
<tr>
<td><code>nbf</code>
</td>
<td>Not Before
</td>
<td>Identifies the time on which the JWT will start to be accepted for processing. The value must be a NumericDate.
</td></tr>
<tr>
<td><code>iat</code>
</td>
<td>Issued at
</td>
<td>Identifies the time at which the JWT was issued. The value must be a NumericDate.
</td></tr>
<tr>
<td><code>jti</code>
</td>
<td>JWT ID
</td>
<td>Case-sensitive unique identifier of the token even among different issuers.
</td></tr>
<tr>
<th colspan="2" style="background: #ececec; color: black; font-weight: bold; vertical-align: middle; text-align: left;" class="table-rh">Commonly-used header fields
</th>
<td>The following fields are commonly used in the header of a JWT
</td></tr>
<tr>
<td><code>typ</code>
</td>
<td>Token type
</td>
<td>If present, it must be set to a registered <a rel="nofollow" class="external text" href="https://www.iana.org/assignments/media-types/media-types.xhtml">IANA Media Type</a>.
</td></tr>
<tr>
<td><code>cty</code>
</td>
<td>Content type
</td>
<td>If nested signing or encryption is employed, it is recommended to set this to <code>JWT</code>; otherwise, omit this field.<sup id="cite_ref-rfc7519_1-3" class="reference"><a href="#cite_note-rfc7519-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</td></tr>
<tr>
<td><code>alg</code>
</td>
<td>Message authentication code algorithm
</td>
<td>The issuer can freely set an algorithm to verify the signature on the token. However, some supported algorithms are insecure.<sup id="cite_ref-auth0_10-0" class="reference"><a href="#cite_note-auth0-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</td></tr>
<tr>
<td><code>kid</code>
</td>
<td>Key ID
</td>
<td>A hint indicating which key the client used to generate the token signature. The server will match this value to a key on file in order to verify that the signature is valid and the token is authentic.
</td></tr>
<tr>
<td><code>x5c</code>
</td>
<td>x.509 Certificate Chain
</td>
<td>A certificate chain in RFC4945 format corresponding to the private key used to generate the token signature. The server will use this information to verify that the signature is valid and the token is authentic.
</td></tr>
<tr>
<td><code>x5u</code>
</td>
<td>x.509 Certificate Chain URL
</td>
<td>A URL where the server can retrieve a certificate chain corresponding to the private key used to generate the token signature. The server will retrieve and use this information to verify that the signature is authentic.
</td></tr>
<tr>
<td><code>crit</code>
</td>
<td>Critical
</td>
<td>A list of headers that must be understood by the server in order to accept the token as valid
</td></tr>
<tr>
<th>Code
</th>
<th>Name
</th>
<th>Description
</th></tr></tbody></table>
<p>List of currently registered claim names can be obtained from <a href="IANA" class="mw-redirect" title="IANA">IANA</a> JSON Web Token Claims Registry.<sup id="cite_ref-IANAJWT_11-0" class="reference"><a href="#cite_note-IANAJWT-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Implementations">Implementations</h2></div>
<p>JWT implementations exist for many languages and frameworks, including but not limited to:
</p>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */
.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}
/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 20em;">
<ul><li><a href=".NET_Framework" title=".NET Framework">.NET (C# VB.Net etc.)</a><sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup></li>
<li><a href="C_(programming_language)" title="C (programming language)">C</a><sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Clojure" title="Clojure">Clojure</a><sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Common_Lisp" title="Common Lisp">Common Lisp</a><sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Dart_(programming_language)" title="Dart (programming language)">Dart</a><sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Elixir_(programming_language)" title="Elixir (programming language)">Elixir</a><sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Erlang_(programming_language)" title="Erlang (programming language)">Erlang</a></li>
<li><a href="Go_(programming_language)" title="Go (programming language)">Go</a><sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Haskell_(programming_language)" class="mw-redirect" title="Haskell (programming language)">Haskell</a><sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Java_(programming_language)" title="Java (programming language)">Java</a><sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup></li>
<li><a href="JavaScript" title="JavaScript">JavaScript</a><sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Lua_(programming_language)" class="mw-redirect" title="Lua (programming language)">Lua</a><sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Node.js" title="Node.js">Node.js</a><sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup></li>
<li><a href="OCaml" title="OCaml">OCaml</a><sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Perl" title="Perl">Perl</a><sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup></li>
<li><a href="PHP" title="PHP">PHP</a><sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup></li>
<li><a href="PL/SQL" title="PL/SQL">PL/SQL</a><sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup></li>
<li><a href="PowerShell" title="PowerShell">PowerShell</a><sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Python_(programming_language)" title="Python (programming language)">Python</a><sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Racket_(programming_language)" title="Racket (programming language)">Racket</a><sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Raku_(programming_language)" title="Raku (programming language)">Raku</a><sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Ruby_(programming_language)" title="Ruby (programming language)">Ruby</a><sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Rust_(programming_language)" title="Rust (programming language)">Rust</a><sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Scala_(programming_language)" title="Scala (programming language)">Scala</a><sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Swift_(programming_language)" title="Swift (programming language)">Swift</a><sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup></li></ul>
</div>
<div class="mw-heading mw-heading2"><h2 id="Vulnerabilities">Vulnerabilities</h2></div>
<p>JSON web tokens may contain session state. But if project requirements allow session invalidation before JWT expiration, services can no longer trust token assertions by the token alone. To validate that the session stored in the token is not revoked, token assertions must be checked against a <a href="Data_store" title="Data store">data store</a>. This renders the tokens no longer stateless, undermining the primary advantage of JWTs.<sup id="cite_ref-37" class="reference"><a href="#cite_note-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup>
</p><p>Security consultant Tim McLean reported vulnerabilities in some JWT libraries that used the <code>alg</code> field to incorrectly validate tokens, most commonly by accepting a <code>alg=none</code> token. While these vulnerabilities were patched, McLean suggested deprecating the <code>alg</code> field altogether to prevent similar implementation confusion.<sup id="cite_ref-auth0_10-1" class="reference"><a href="#cite_note-auth0-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> Still, new <code>alg=none</code> vulnerabilities are still being found in the wild, with four <a href="Common_Vulnerabilities_and_Exposures" title="Common Vulnerabilities and Exposures">CVEs</a> filed in the 2018-2021 period having this cause.<sup id="cite_ref-38" class="reference"><a href="#cite_note-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup>
</p><p>With proper design, developers can address algorithm vulnerabilities by taking precautions:<sup id="cite_ref-vuln_39-0" class="reference"><a href="#cite_note-vuln-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-40" class="reference"><a href="#cite_note-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup>
</p>
<ol><li>Never let the JWT header alone drive verification</li>
<li>Know the algorithms (avoid depending on the <code class="mw-highlight mw-highlight-lang-text mw-content-ltr" style="" dir="ltr">alg</code> field alone)</li>
<li>Use an appropriate key size</li></ol>
<p>Several JWT libraries were found to be vulnerable to an <a href="Elliptic-curve_cryptography#Invalid_curve_attack" title="Elliptic-curve cryptography">invalid Elliptic-curve attack</a> in 2017.<sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup>
</p><p>Some have argued that JSON web tokens are difficult to use securely due to the many different encryption algorithms and options available in the standard, and that alternate standards should be used instead for both web frontends<sup id="cite_ref-42" class="reference"><a href="#cite_note-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup> and backends.<sup id="cite_ref-43" class="reference"><a href="#cite_note-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="API_key" title="API key">API key</a></li>
<li><a href="Access_token" title="Access token">Access token</a></li>
<li><a href="Basic_access_authentication" title="Basic access authentication">Basic access authentication</a></li>
<li><a href="Digest_access_authentication" title="Digest access authentication">Digest access authentication</a></li>
<li><a href="Claims-based_identity" title="Claims-based identity">Claims-based identity</a></li>
<li><a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP header</a></li>
<li>Concise Binary Object Representation (<a href="CBOR" title="CBOR">CBOR</a>)</li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-rfc7519-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-rfc7519_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-rfc7519_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-rfc7519_1-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-rfc7519_1-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFJonesBradleySakimura2015" class="citation cs1">Jones, Michael B.; Bradley, Bradley; Sakimura, Sakimura (May 2015). <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7519"><i>JSON Web Token (JWT)</i></a>. <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">IETF</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC7519">10.17487/RFC7519</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/2070-1721">2070-1721</a>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7519">7519</a>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite id="CITEREFNickel2016" class="citation book cs1">Nickel, Jochen (2016). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=Q4dcDgAAQBAJ&pg=PA84"><i>Mastering Identity and Access Management with Microsoft Azure</i></a>. Packt Publishing. p. 84. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>9781785887888</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">July 20,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-jwtintro-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-jwtintro_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-jwtintro_3-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://jwt.io/introduction/">"JWT.IO - JSON Web Tokens Introduction"</a>. <i>jwt.io</i><span class="reference-accessdate">. Retrieved <span class="nowrap">July 20,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFSevilleja" class="citation web cs1">Sevilleja, Chris. <a rel="nofollow" class="external text" href="https://scotch.io/tutorials/the-anatomy-of-a-json-web-token">"The Anatomy of a JSON Web Token"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20150518082002/https://developer.atlassian.com/static/connect/docs/latest/concepts/understanding-jwt.html">"Atlassian Connect Documentation"</a>. <i>developer.atlassian.com</i>. Archived from <a rel="nofollow" class="external text" href="https://developer.atlassian.com/static/connect/docs/latest/concepts/understanding-jwt.html">the original</a> on May 18, 2015<span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-:1-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-:1_6-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFJonesBradleySakimura2015" class="citation journal cs1">Jones, Michael B.; Bradley, John; Sakimura, Nat (May 2015). <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/draft-ietf-jose-json-web-signature-41">"draft-ietf-jose-json-web-signature-41 - JSON Web Signature (JWS)"</a>. <i>tools.ietf.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-:2-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-:2_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFJonesHildebrand2015" class="citation journal cs1">Jones, Michael B.; Hildebrand, Joe (May 2015). <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/draft-ietf-jose-json-web-encryption-40">"draft-ietf-jose-json-web-encryption-40 - JSON Web Encryption (JWE)"</a>. <i>tools.ietf.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFJones2015" class="citation journal cs1">Jones, Michael B. (May 2015). <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/draft-ietf-jose-json-web-algorithms-40">"draft-ietf-jose-json-web-algorithms-40 - JSON Web Algorithms (JWA)"</a>. <i>tools.ietf.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 8,</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-rfc-7519-section-4.1.4-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-rfc-7519-section-4.1.4_9-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFJonesBradleySakimura2015" class="citation cs1">Jones, Michael B.; Bradley, Bradley; Sakimura, Sakimura (May 2015). <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7519#section-4.1.4">""exp" (Expiration Time) Claim"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7519"><i>JSON Web Token (JWT)</i></a>. <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">IETF</a>. sec. 4.1.4. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC7519">10.17487/RFC7519</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/2070-1721">2070-1721</a>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7519">7519</a>.</cite></span>
</li>
<li id="cite_note-auth0-10"><span class="mw-cite-backlink">^ <a href="#cite_ref-auth0_10-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-auth0_10-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFMcLean2015" class="citation web cs1">McLean, Tim (March 31, 2015). <a rel="nofollow" class="external text" href="https://www.chosenplaintext.ca/2015/03/31/jwt-algorithm-confusion.html">"Critical vulnerabilities in JSON Web Token libraries"</a>. Auth0<span class="reference-accessdate">. Retrieved <span class="nowrap">March 29,</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-IANAJWT-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-IANAJWT_11-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.iana.org/assignments/jwt/jwt.xhtml/">"JSON Web Token (JWT)"</a>. <i>IANA</i>. January 23, 2015<span class="reference-accessdate">. Retrieved <span class="nowrap">December 5,</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/jwt-dotnet/jwt">jwt-dotnet</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/benmcollins/libjwt">libjwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/liquidz/clj-jwt">"liquidz/clj-jwt"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/gschjetne/cljwt">cljwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/deftomat/JustJWT">JustJWT</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/bryanjos/joken">"bryanjos/joken"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/golang-jwt/jwt">"golang-jwt/jwt"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">January 8,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://hackage.haskell.org/package/jose">"jose: JSON Object Signing and Encryption (JOSE) and JSON Web Token (JWT) library"</a>. <i>Hackage</i><span class="reference-accessdate">. Retrieved <span class="nowrap">December 25,</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/auth0/java-jwt">auth0/java-jwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/kjur/jsrsasign">"kjur/jsrsasign"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/SkyLothar/lua-resty-jwt">"SkyLothar/lua-resty-jwt"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.npmjs.com/package/jsonwebtoken">"jsonwebtoken"</a>. <i>npm</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 7,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/besport/ocaml-jwt">ocaml-jwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://metacpan.org/pod/Crypt::JWT">Crypt::JWT</a> on <a href="Cpan.org" class="mw-redirect" title="Cpan.org">cpan.org</a></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/lcobucci/jwt">lcobucci/jwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite id="CITEREFEgan2019" class="citation cs2">Egan, Morten (February 7, 2019), <a rel="nofollow" class="external text" href="https://github.com/morten-egan/jwt_ninja"><i>GitHub - morten-egan/jwt_ninja: PLSQL Implementation of JSON Web Tokens.</i></a><span class="reference-accessdate">, retrieved <span class="nowrap">March 14,</span> 2019</span></cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/SP3269/posh-jwt">"SP3269/posh-jwt"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">August 1,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/jpadilla/pyjwt">"jpadilla/pyjwt"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">March 21,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://pkgs.racket-lang.org/package/net-jwt">net-jwt</a> on pkgs.racket-lang.org</span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/jamesalbert/JSON-WebToken">JSON-WebToken</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/jwt/ruby-jwt">ruby-jwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/Keats/jsonwebtoken">jsonwebtoken</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/mikkyang/rust-jwt">rust-jwt</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-35">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/pauldijou/jwt-scala">jwt-scala</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external autonumber" href="https://github.com/kylef/JSONWebToken.swift">[1]</a> on <a href="Github.com" class="mw-redirect" title="Github.com">github.com</a></span>
</li>
<li id="cite_note-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-37">^</a></b></span> <span class="reference-text"><cite id="CITEREFSlootweg" class="citation web cs1">Slootweg, Sven. <a rel="nofollow" class="external text" href="http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/">"Stop using JWT for sessions"</a>. <i>joepie91 Ramblings</i><span class="reference-accessdate">. Retrieved <span class="nowrap">August 1,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-38">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=jwt+none">"CVE - Search Results"</a>. <i>cve.mitre.org</i>.</cite></span>
</li>
<li id="cite_note-vuln-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-vuln_39-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://connect2id.com/products/nimbus-jose-jwt/vulnerabilities">"Common JWT security vulnerabilities and how to avoid them"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">May 14,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-40">^</a></b></span> <span class="reference-text"><cite id="CITEREFAndreas" class="citation web cs1">Andreas, Happe. <a rel="nofollow" class="external text" href="https://snikt.net/blog/2019/05/16/jwt-signature-vs-mac-attacks/">"JWT: Signature vs MAC attacks"</a>. <i>snikt.net</i><span class="reference-accessdate">. Retrieved <span class="nowrap">May 27,</span> 2019</span>.</cite></span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://auth0.com/blog/critical-vulnerability-in-json-web-encryption/">"Critical Vulnerability in JSON Web Encryption"</a>. <i>Auth0 - Blog</i><span class="reference-accessdate">. Retrieved <span class="nowrap">October 14,</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-42">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid">"No Way, JOSE! Javascript Object Signing and Encryption is a Bad Standard That Everyone Should Avoid - Paragon Initiative Enterprises Blog"</a>. <i>paragonie.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">October 13,</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-43">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://authzed.com/blog/pitfalls-of-jwt-authorization">"Pitfalls of JWT Authorization"</a>. <i>authzed.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">November 16,</span> 2023</span>.</cite></span>
</li>
</ol></div>
<ul><li><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7519">7519</a></li>
<li><a rel="nofollow" class="external text" href="https://jwt.io/">jwt.io</a> – specialized website about JWT with tools and documentation, maintained by Auth0</li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Data_exchange_formats144" style="padding:3px"><table class="nowraplinks mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div id="Data_exchange_formats144" style="font-size:114%;margin:0 4em"><a href="Data_exchange" title="Data exchange">Data exchange</a> formats</div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Human-readable_medium_and_data" title="Human-readable medium and data">Human<br>readable</a></th><td class="navbox-list-with-group navbox-list navbox-odd hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Atom_(web_standard)" title="Atom (web standard)">Atom</a></li>
<li><a href="Comma-separated_values" title="Comma-separated values">CSV</a></li>
<li><a href="EDIFACT" title="EDIFACT">EDIFACT</a></li>
<li><a href="JSON" title="JSON">JSON</a>
<ul><li><a href="JSON_Web_Encryption" title="JSON Web Encryption">Web Encryption</a></li>
<li><a href="JSON_Web_Signature" title="JSON Web Signature">Web Signature</a></li></ul></li>
<li><a href="Property_list" title="Property list">Property list</a></li>
<li><a href="Resource_Description_Framework" title="Resource Description Framework">RDF</a></li>
<li><a href="Rebol" title="Rebol">Rebol</a></li>
<li><a href="TOML" title="TOML">TOML</a></li>
<li><a href="XML" title="XML">XML</a></li>
<li><a href="YAML" title="YAML">YAML</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Binary_file" title="Binary file">Binary</a></th><td class="navbox-list-with-group navbox-list navbox-even hlist" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Action_Message_Format" title="Action Message Format">AMF</a></li>
<li><a href="Ascii85" title="Ascii85">Ascii85</a></li>
<li><a href="ASN.1" title="ASN.1">ASN.1</a>
<ul><li><a href="Structure_of_Management_Information" title="Structure of Management Information">SMI</a></li></ul></li>
<li><a href="Apache_Avro" title="Apache Avro">Avro</a></li>
<li><a href="Base32" title="Base32">Base32</a></li>
<li><a href="Base64" title="Base64">Base64</a></li>
<li><a href="Bencode" title="Bencode">Bencode</a></li>
<li><a href="BSON" title="BSON">BSON</a>
<ul><li><a href="UBJSON" title="UBJSON">UBJSON</a></li></ul></li>
<li><a href="Cap'n_Proto" title="Cap'n Proto">Cap'n Proto</a></li>
<li><a href="CBOR" title="CBOR">CBOR</a></li>
<li><a href="FlatBuffers" title="FlatBuffers">FlatBuffers</a></li>
<li><a href="MessagePack" title="MessagePack">MessagePack</a></li>
<li><a href="Property_list" title="Property list">Property list</a></li>
<li><a href="Protocol_Buffers" title="Protocol Buffers">Protocol Buffers</a></li>
<li><a href="Apache_Thrift" title="Apache Thrift">Thrift</a></li>
<li><a href="Cyphal" title="Cyphal">Cyphal</a> DSDL</li>
<li><a href="External_Data_Representation" title="External Data Representation">XDR</a></li>
<li><a href="Uuencoding" title="Uuencoding">uuencode</a></li>
<li><a href="YEnc" title="YEnc">yEnc</a></li></ul>
</div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div><a href="Comparison_of_data-serialization_formats" title="Comparison of data-serialization formats">Comparison of data-serialization formats</a></div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-05-26" href="https://en.wikipedia.org/wiki/?title=JSON_Web_Token&oldid=1292271323">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>