Step by step
The example above, written out — the same steps the animation plays.
- 1Sign in → get a token. After Asha signs in, the server issues a JWT: proof of who she is that the app sends with every request.
- 2Header. JSON saying how the token is signed (HMAC-SHA256), encoded as base64url.
- 3Payload. The claims: who (sub), what role, and when it expires (exp). Also just base64url — encoded, not encrypted.
- 4Signature. HMAC-SHA256(header.payload, secret) — only the server knows the secret. Hex: 0d8a49cc9e4f534d14b1eb26…
- 5The token. header.payload.signature — the app stores it and sends it as Authorization: Bearer <token>.
- 6Server: recompute the signature. HMAC(header.payload) with its secret = DYpJzJ5PU00Usesm… The token says DYpJzJ5PU00Usesm…
- 7Check the expiry. exp = 1791277200; now = 1791273600. Still valid for an hour.
- 8200 — welcome, Asha. Signature valid and not expired: the server trusts the claims without a database lookup. That is the point of a JWT — and why you can't easily revoke one before it expires.
What's happening?
- The header and payload are JSON, base64url-encoded — encoded, not encrypted, so anyone can read them.
- The signature is HMAC-SHA256 of header.payload with a secret only the server knows.
- On each request the server recomputes the signature: any edit to the token breaks it, and an expired exp is rejected.
Where you'll meet it
API authentication (Authorization: Bearer …), single sign-on (OpenID Connect ID tokens) and short-lived access tokens paired with refresh tokens.
Common mistake
Putting secrets or personal data in the payload, or accepting tokens without checking the signature, the algorithm and the expiry.
FAQ
Is the signature here real?
Yes — real HMAC-SHA256 computed in your browser, the same bytes any JWT library produces with this secret.
Can a JWT be revoked?
Not by itself: it stays valid until it expires. Keep access tokens short-lived, or check a deny-list for logout.
HS256 or RS256?
HS256 uses one shared secret to sign and verify; RS256 signs with a private key and lets anyone verify with the public key — better when many services verify.