JWT

From Wiki RB4
Revision as of 00:13, 19 February 2022 by UweHeuer (talk | contribs) (→‎Jason Web Token (JWT))
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Jason Web Token (JWT)[edit]

  • pronounced as jott
  • consists of
<HEADER>.<PAYLOAD>.<SIGNATURE>
  • <PAYLOAD> tells who is making the request
  • <SIGNATURE> ensure the correctness (not tampered, trusted source)
    • <SIGNATURE> = function(<HEADER>,<PAYLOAD>,<SECRET>)
    • <SECRET> is known by the authentication service and by the application server

Resources[edit]