Resta saysA JWT has three base64url parts: header, payload, and signature — dot-separated.
xxxxx.yyyyy.zzzzz — the header names the algorithm, the payload holds the claims (NOT secret — anyone can decode it), and the signature is the header+payload signed with a secret/key. The server recomputes the signature to verify integrity. Because the payload is only encoded, never store sensitive data in it.
Power-ups you unlock
header.payload.signature (base64url)
Header = algorithm; payload = claims
Payload is readable — not encrypted
Signature proves integrity
The 401 Bandit attacks — common mistakes
Believing the payload is hidden
Storing PII/secrets in claims
Skipping signature verification on the server
Boss battleDecode the three parts of a JWT and identify which is verifiable, not secret.