freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #40 of 45

jwt · header · payload · signature

RestaVSThe 401 Bandit
Resta saysA JWT has three base64url parts: header, payload, and signature — dot-separated.

xxxxx.yyyyy.zzzzz — the header names the algorithm, the payload holds the claims (NOT secret — anyone can decode it), and the signature is the header+payload signed with a secret/key. The server recomputes the signature to verify integrity. Because the payload is only encoded, never store sensitive data in it.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleDecode the three parts of a JWT and identify which is verifiable, not secret.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>header:    { "alg": "HS256", "typ": "JWT" }
payload:   { "sub": 42, "exp": 1735689600 }  ← readable
signature: HMAC(header.payload, secret)       ← verify</pre></body></html>
▶ Open the interactive comic issue
‹ Jwt · The Self-Contained TokenRefresh Tokens · Keeping Sessions Alive ›