JWT 结构与声明
分解 JWT 的三个部分(标头、载荷和签名),并了解标准声明和自定义声明。
JWT 结构与声明 是 CoddyKit 上的免费 Spring Security 6 & JWT Authentication 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Security 6 & JWT Authentication 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
What's Inside a JWT?
JSON Web Tokens (JWTs) might look like long, random strings, but they have a very clear and organized structure.
A JWT is composed of three distinct parts, each separated by a dot (.):
- Header
- Payload
- Signature
Think of it like a sealed letter: the header is information about the letter itself, the payload is the message inside, and the signature is the wax seal proving its authenticity.
Part 1: The Header
The Header is the first part of a JWT. It's a JSON object that contains metadata about the token itself, primarily telling us what algorithm was used to sign the token.
It typically includes two key elements:
alg(Algorithm): Specifies the cryptographic algorithm used for signing the token (e.g.,HS256for HMAC SHA-256,RS256for RSA SHA-256).typ(Type): Indicates the type of token, which is almost alwaysJWT.
Header Example
Here's what a typical JWT header looks like as a JSON object:
{
"alg": "HS256",
"typ": "JWT"
}Before being included in the JWT string, this JSON object is Base64Url encoded. This process converts the JSON into a web-safe string.
Part 2: The Payload (Claims)
The Payload is the second part of the JWT and is arguably the most important. It's also a JSON object, but this one contains the actual data, known as "claims."
Claims are statements about an entity (usually the user) and additional data. They are essentially key-value pairs that carry information such as:
- User ID
- User roles or permissions
- Token expiration time
Standard Claims - The Basics
JWTs define a set of "standard claims" that are recommended for common use. While optional, using them helps ensure interoperability.
Some common standard claims include:
iss(Issuer): Identifies the principal that issued the JWT (e.g.,auth.example.com).sub(Subject): Identifies the principal that is the subject of the JWT (e.g., a user ID likeuser123).exp(Expiration Time): The time after which the JWT MUST NOT be accepted for processing. It's a Unix timestamp.iat(Issued At): The time at which the JWT was issued. Also a Unix timestamp.aud(Audience): Identifies the recipients that the JWT is intended for (e.g.,api.example.com).
Custom Claims - Your Data
In addition to standard claims, you can include any custom claims in the payload that are relevant to your application.
This allows you to store application-specific data directly within the token, such as:
- User-specific roles (e.g.,
admin,editor) - Permissions (e.g.,
read:product,write:order) - Unique identifiers specific to your system
Keep custom claims concise to minimize the overall token size, which helps with performance.
Payload Example
Here's an example of a JWT payload containing both standard and custom claims:
{
"sub": "user123",
"name": "Alice Smith",
"roles": ["admin", "editor"],
"iat": 1678886400,
"exp": 1678890000
}Like the header, this JSON object is also Base64Url encoded before becoming part of the full JWT string.
Part 3: The Signature
The Signature is the third and final part of a JWT. It's critical for security, as it serves two main purposes:
- Integrity: Verifies that the token hasn't been tampered with since it was issued.
- Authenticity: Confirms that the token was indeed created by the expected issuer.
Without a valid signature, the token should be considered invalid and untrustworthy.
How the Signature is Made
The signature is created by taking the Base64Url encoded header, the Base64Url encoded payload, and a secret key, then running them through the cryptographic algorithm specified in the header.
Conceptually, it works like this:
signature = Algorithm(
Base64Url(header) + "." +
Base64Url(payload),
secret_key
)The resulting signature is then also Base64Url encoded and appended to the JWT string, completing its three-part structure.
Quick Check: JWT Claims
Test your knowledge on JWT claims!
Recap: The JWT Blueprint
Great job! You now understand the fundamental structure of a JSON Web Token.
- The Header contains metadata about the token, including the signing
algorithm andtype. - The Payload carries the actual data in the form of "claims," which can be standard (like
iss,sub,exp) or custom. - The Signature is a cryptographic hash that ensures the token's integrity and authenticity, preventing tampering and verifying the sender.
Understanding these three distinct parts is crucial for effectively working with and securing applications using JWTs.
常见问题解答
「JWT 结构与声明」课时是免费的吗?
是的 — 「JWT 结构与声明」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Security 6 & JWT Authentication 课程的其余内容,请升级到 CoddyKit PRO。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。
「JWT 结构与声明」这节课中我会学到什么?
分解 JWT 的三个部分(标头、载荷和签名),并了解标准声明和自定义声明。 你通过在浏览器中直接运行的动手代码来练习 Spring Security 6 & JWT Authentication,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Spring Security 6 & JWT Authentication 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Spring Security 6 & JWT Authentication 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「JWT 结构与声明」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Spring Security 6 & JWT Authentication 课中编写并运行代码吗?
能。每节 Spring Security 6 & JWT Authentication 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。