Short answer
A JSON Web Token is a compact, signed token with three base64url parts: header, payload (claims) and signature. Servers verify the signature to trust the claims without a database lookup. JWTs are signed, not encrypted, so never put secrets in them; keep them short-lived, validate algorithm, issuer, audience and expiry, and plan for revocation.
Common pitfalls
- Accepting the “none” algorithm or letting the token choose the algorithm.
- Long-lived tokens that cannot be revoked after a compromise.
- Storing tokens where scripts can read them, increasing XSS impact.
- Skipping audience and issuer checks.
Sessions vs JWTs
Server-side sessions are easy to revoke and keep data private. JWTs suit distributed verification between services. Many systems combine short-lived JWT access tokens with revocable refresh tokens.
How to answer it in an interview
- Stress “signed, not encrypted”.
- Describe a revocation approach such as short expiry plus refresh-token rotation.