DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk5 min

JWT Tokens Explained: Identity, Context, and Permissions

JWTs carry claims, but those claims only have meaning within an application’s validation rules. Understand identity, audience, permissions, and OAuth access-token checks.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A JWT is a compact format for representing claims, not a complete authorization decision. Its claims can identify an issuer and subject, name intended recipients, describe validity times, or carry authorization data—but an application must define which claims it requires and how to validate and use them. In particular, a signed JWT is not confidential: its contents are not hidden unless the token is encrypted.

What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe representation of a set of claims—statements about a subject—transferred between parties. The format is defined by RFC 7519. A JWT describes data; by itself, it does not establish that the data is trustworthy or decide what a receiver should permit.

As an Amazon Associate I earn from qualifying purchases.

JWTs can be protected in different ways. A JSON Web Signature (JWS) can provide a digital signature or message authentication code (MAC), helping a receiver detect changes and, depending on the key arrangement, verify who created the token. A JSON Web Encryption (JWE) encrypts the contents for confidentiality. A JWT may also be nested. Base64url-encoded claims in a signed JWS are readable by anyone who obtains the token; signing is not encryption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does a JWT token contain?

A JWT commonly has a header and a claims set, with the protection or encryption structure determined by whether it uses JWS, JWE, or nesting. Claims are name/value pairs. RFC 7519 defines registered claim names and their meanings, but it does not require every JWT application to include every registered claim. An application or token profile sets its own requirements; the IANA JSON Web Token Registry records registered claim names and related values.

#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Claim Meaning What the receiver needs to decide
iss Issuer: the principal that issued the JWT. Is this an issuer the application trusts, and is the signing key associated with that issuer?
sub Subject: the principal that is the token’s subject. What does this subject identifier mean in this application, and is it valid here?
aud Audience: intended recipient or recipients. Is this service among the intended recipients?
exp Expiration time. Has the token expired under the application’s time and clock-skew rules?
nbf Not-before time. Is the token valid yet?
iat Issued-at time. When was it issued, and does that fit any application-specific age or issuance rules?
jti JWT identifier. Does the application use this identifier for replay detection, revocation, or another defined purpose?

These meanings do not make the claims universally mandatory. For example, an application can require an audience claim and reject a token without it even though the generic JWT specification does not require that claim in every JWT. A profile can make a defined set mandatory for tokens that follow that profile.

How do JWT tokens work?

A party creates a claims set, places it in a JWT structure, and applies the protection required by its use case. A receiver then validates the token according to the relevant application or profile rules before relying on its claims. Those rules determine what counts as an acceptable issuer, subject, audience, token type, cryptographic algorithm, key, and validity period.

Rank #2
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
  • There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
  • Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
  • Reorder SKU: LOG-100-M3CW-PP(Security-Report)

Identity: who issued it, and who is its subject?

iss identifies the issuer; sub identifies the subject. They answer different questions. In a user-involved flow the subject may be a person, while in an OAuth client-credentials flow it may be a client application. The receiver must understand the subject identifier’s semantics in its own context rather than treating any syntactically valid value as an identity it recognizes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Context: where and when should it be accepted?

aud identifies the intended recipient or recipients, while nbf and exp constrain the time window in which a token may be accepted. A service should check that it is an intended audience and that the token is currently valid. The token’s type also matters: a token issued for one protocol role should not automatically be accepted as another kind of token.

Permissions: what authorization information does it carry?

A claim such as scope can represent authorization information. Other applications may use attributes such as groups, roles, or entitlements. These are inputs to policy, not self-executing permission grants. A resource server still needs to consider the requested resource, operation, and relevant runtime context before allowing a request.

How do I validate a JWT access token?

Validation rules depend on the token’s purpose. OAuth 2.0 does not mandate one universal access-token format. Opaque access tokens are possible, and RFC 9068 defines a particular profile for JWT-formatted OAuth access tokens. The checks below apply to that profile, not automatically to every JWT or every OAuth deployment.

For an RFC 9068 access token, the required claims are iss, exp, aud, sub, client_id, iat, and jti. The profile requires a signed token, disallows alg: none, and uses the explicit token type at+jwt to distinguish an access token from other JWT kinds, including OpenID Connect ID tokens.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Use the right validation profile. Determine that the endpoint expects an RFC 9068 JWT access token, or apply the separate rules defined for the token type it expects. Do not accept an ID token as an access token simply because both are JWTs.
  2. Check the token type and structure. For RFC 9068, verify the explicit access-token type (at+jwt) and reject a token that does not meet the profile’s token-format requirements.
  3. Verify the signature with a trusted issuer key. Obtain keys through the issuer’s trusted configuration or established key-distribution mechanism, and check that the key belongs to the expected issuer. RFC 9068 recommends asymmetric signing to simplify distribution of validation keys. Reject alg: none.
  4. Match the issuer exactly. Compare iss with the issuer configured for this resource server. A valid signature alone does not establish that the issuer is one this service trusts.
  5. Check the audience for this resource server. Confirm that aud includes the service or resource that is processing the request. Do not accept a token intended only for a different service.
  6. Check required claims and time validity. Enforce the profile’s required claims, including sub, client_id, iat, jti, and exp; reject expired tokens and apply any relevant nbf and local time-handling rules.
  7. Apply authorization policy. Interpret scope and any other authorization attributes according to the application, then decide whether they cover the specific resource and action in the current request.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why a valid signature is not enough

A signature can show that protected token contents have not been altered and that the token was signed with a particular key. It does not prove that the signer is trusted for this application, that the token targets this service, that the subject has the expected meaning, or that the requested action is allowed. RFC 8725, the JWT Best Current Practices, says applications must bind trusted cryptographic keys to the relevant issuer and validate subject semantics when a subject is present. When an issuer serves multiple applications or relying parties, the audience must identify the intended recipient and that recipient must check it.

Do not blindly follow jku or x5u URLs supplied in an untrusted token header to fetch keys. Arbitrary URL retrieval can expose a server to server-side request forgery. Use trusted issuer configuration, and use mutually exclusive validation rules for different token kinds from the same issuer to reduce the risk that a token is substituted into the wrong context.

JWT versus opaque access token

JWT and opaque access tokens are alternative formats, not a standards-established ranking of speed or security. RFC 6749 leaves the access-token format open; RFC 9068 standardizes a JWT profile with particular claims, typing, and validation requirements. The appropriate format depends on an authorization system’s design and the checks its resource servers are required to perform.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.