JWT Token Architecture & Cryptographic Verification Invariants
JSON Web Tokens conform to the RFC 7519 open standard for stateless claim exchange across distributed microservices.
1. Dot-Delimited JWS Token Structure
Base64Url(Header).Base64Url(Payload).Base64Url(Signature)
2. HMAC-SHA256 Signature Verification Invariant
Signature=HMAC-SHA256( B64(Header) ∥ "." ∥ B64(Payload), SecretKey )
Step-by-Step JWT Claims Inspection Breakdown
Step 1: Parse Header Metadata Segment
{ "alg": "HS256", "typ": "JWT" }: Declares symmetric HMAC-SHA256 signing.Step 2: Base64Url Decode Claims Payload
{ "sub": "1234567890", "role": "user", "exp": 2082726400 }Step 3: Evaluate Expiration & Temporal Validity
Status=Active & Valid Token (Expiry > Current Timestamp)
Standard JWT Reserved Claims Reference
| Claim Key | Full Name | Value Type | RFC 7519 Purpose |
|---|---|---|---|
| iss | Issuer | String / URI | Identifies the principal authority that issued the token |
| sub | Subject | String (User ID) | Unique identifier of the entity or user |
| exp | Expiration Time | NumericDate (Seconds) | Timestamp on or after which the token must not be accepted |
| iat | Issued At | NumericDate (Seconds) | Timestamp at which the JWT was created |
| nbf | Not Before | NumericDate (Seconds) | Timestamp before which the JWT must not be accepted |