LearnThatStack Ace your next interview
JWT & Token-Based Auth · question
Q.02 of 18

What are the three parts of a JWT token? Explain each part.

beginner
← All JWT & Token-Based Auth questions
Re-explain

Header:

{
  "alg": "HS256",
  "typ": "JWT"
}

Contains metadata about the token, including the signing algorithm and token type.

Payload:

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022,
  "exp": 1516242622
}

Contains claims - statements about an entity (typically the user) and additional data. Claims can be registered, public, or private.

Signature:

HMACSHA256(
  base64UrlEncode(header) + "." +
  base64UrlEncode(payload),
  secret
)

Used to verify that the sender of the JWT is who it says it is and to ensure that the message wasn't changed along the way.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

The model's verdict: “

The interactive diagram is below the answer - jump to diagram ↓

This answer is explained by a shared concept diagram - open

Tailored explanation · switch back to · ·
Point the redraw:
How well did you know this?
AI:

Saved in this browser - sign in to keep your review list.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Interview lens

Likely follow-ups, what you can say, and the weak answers to avoid.

Sign in free to open it Free account - the lens opens as soon as you're back.

← Back to all JWT & Token-Based Auth questions
Pro · $10/mo

16 of 18 JWT & Token-Based Auth answers are gated.

Full answers, code samples, AI explanations - simpler, deeper, or as an interactive diagram. Cancel anytime.

  • Full answers + code
  • AI explain - simpler, deeper, or visualized
  • 1,000 AI credits / month
  • Cancel anytime