The Anatomy of JSON Web Tokens: RFC 7519 and JWS Architecture
In modern web security, OAuth 2.0 authorization frameworks, and OpenID Connect (OIDC) identity layers, JSON Web Tokens (JWT) serve as the primary compact, URL-safe means of representing claims between two parties. Defined under IETF RFC 7519 and secured via JSON Web Signature (JWS, RFC 7515), a JWT encapsulates identity information without requiring round-trip database session lookups on distributed microservices.
The Three Tripartite Token Components
A standard signed JWT consists of three distinct Base64URL-encoded strings separated by dot (.) delimiters:
| Segment | Color Indicator | Content Schema | Security Purpose |
|---|---|---|---|
| 1. Header | Red / Rose | { "alg": "RS256", "typ": "JWT" } | Declares cryptographic algorithm and token type. |
| 2. Payload | Indigo / Purple | { "sub": "123", "exp": 1774886400 } | Contains identity claims, roles, and expiration dates. |
| 3. Signature | Cyan / Blue | HMACSHA256(base64Url(H) + "." + base64Url(P), secret) | Cryptographically prevents payload tampering and forgery. |
Registered Claim Names and Temporal Validation
RFC 7519 reserves a set of standardized claims providing interoperable authorization semantics:
iss(Issuer): Identifies the principal security authority that issued the token (e.g.https://auth.company.com/).sub(Subject): The unique identifier of the user or machine entity.aud(Audience): Identifies the intended recipients (e.g., target API microservices).exp(Expiration Time): The UTC timestamp after which the token MUST NOT be accepted.nbf(Not Before) &iat(Issued At): Delineate the temporal validity window of the token.
Architectural Vulnerabilities and Client-Side Token Hygiene
While JWTs solve horizontal stateless scaling challenges, developers must guard against common pitfalls:
- Confidentiality Myth: Standard JWTs are signed, not encrypted. Any client or intermediary can decode the Base64URL payload. Never store passwords, PII, or unencrypted secrets in JWT claims.
- Storage Vector Risks: Storing JWTs in browser
localStorageexposes tokens to Cross-Site Scripting (XSS) extraction. Storing access tokens inHttpOnly, SameSite=Strictcookies mitigates automated exfiltration.