freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #39 of 45

jwt · the self-contained token

RestaVSThe 401 Bandit
Resta saysA JWT is a self-contained, signed token carrying claims the server can verify without a lookup.

A JSON Web Token encodes claims (user id, expiry, scopes) and is signed so the server can verify it wasn't tampered with — no database lookup needed to trust it. That makes JWTs stateless and scalable. The trade-off: you can't easily revoke one before it expires, so keep lifetimes short and pair with refresh tokens.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain the revocation trade-off of stateless JWTs.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>JWT = header.payload.signature
server verifies signature → trusts claims
no DB hit, but can’t un-issue before expiry</pre></body></html>
▶ Open the interactive comic issue
‹ Openid Connect · Oauth + IdentityJwt · Header · Payload · Signature ›