What is a JWT?
A JSON Web Token is three base64url-encoded segments joined by dots: a header naming the signing algorithm, a payload of claims, and a signature. The signature lets a receiver prove the token came from a trusted issuer and wasn't modified — but the payload is only encoded, not encrypted: anyone holding the token can read it.
That's the single most important thing to internalize: a signed JWT (JWS) provides integrity and authenticity, never confidentiality. When the payload must be secret, JWE encryption exists for exactly that. The full article covers the anatomy of each segment, the token lifecycle from issuer to verifier, and where JWTs fit in OAuth 2.0 and OpenID Connect — or jump straight to decoding a real token.