A Practical Guide to JSON Web Tokens
A compact, signed token format, known as JWT, used to pass claims such as user identity between systems, often in APIs and single sign-on.
Why does it matter?
JWTs are widely used and widely misused, and implementation mistakes can let attackers forge or reuse tokens.
What are the numbers?
- Standard RFC 7519
- Structure header, payload and signature
- Signature proves integrity but does not encrypt the payload
- Expiry the exp claim limits token lifetime
What should I do?
- Use well-maintained libraries
- Validate signature, issuer, audience and expiry
- Keep token lifetimes short
- Never put sensitive data in the payload
- Plan for token revocation
What should I avoid?
Avoid:
- Accepting the none algorithm
- Long-lived tokens with no revocation
- Storing sensitive data in tokens
- Storing tokens where scripts can read them without considering XSS
When should I get help?
Short answer Bring in help when designing API authentication or single sign-on.
Where this comes from
- RFC Editor — RFC 7519 JSON Web Token
- OWASP — JSON Web Token Cheat Sheet for Java
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.