JSON Web Token (JWT) enable secure information transmission between different systems. They are particularly useful for authentication and authorization in web applications.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Technical building block: can be automated, integrated, or operated.
Concrete cog in the system that works inside larger relationships.
A JSON Web Token is a compact, signed token that carries claims between parties as a JSON structure.
JWT grew from the need to pass identity and authorization information compactly between distributed web applications. Auth0 helped drive practical adoption; the specification was standardized as RFC 7519 in 2015.
A token contains a header, payload, and signature separated by dots. The recipient checks the algorithm and signature, then evaluates claims such as issuer, audience, and expiry.
It describes the type and signing algorithm.
The payload carries statements about subject and context.
It protects verifiable token integrity.
JWT fits stateless authentication and delegated authorization. Key management, expiry, revocation, safe claims, and separating signing from encryption are essential.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.