Glossary
71 definitions covering JSON Web Tokens, signing algorithms, standard claims, secrets management, and cryptographic primitives. Each term includes a plain-language definition, why it matters for production security, optional code examples, and links to related tools and comparisons.
New to JWTs? Start with JSON Web Token, JWT secret keys, and HS256. For side-by-side decisions, see our comparison guides.
Try JWT Token Validator — open toolA
Access Token
Access tokens authorize API requests. Learn how JWT access tokens differ from refresh tokens.
alg Header Parameter
The alg header declares the signing algorithm. Learn why hardcoded algorithm validation is mandatory.
alg:none (Unsecured JWT)
What alg:none means in JWTs, why unsecured tokens are dangerous, and how to reject them with algorithm allowlists.
Algorithm Confusion Attack
Algorithm confusion lets attackers forge JWTs by switching RS256 to HS256. Learn prevention steps.
aud (Audience) Claim
The aud claim names the intended recipients of a JWT. Learn why audience checks stop cross-service token reuse.
B
C
CORS (Cross-Origin Resource Sharing)
CORS controls cross-origin browser access to APIs that accept JWT bearer tokens.
CORS with JWT APIs
How CORS interacts with JWT Authorization headers and cookie credentials, and common misconfigurations that break or weaken APIs.
Cryptographic Entropy
High entropy is required for JWT secrets and jti values. Learn how randomness affects security.
Cryptographic Salt
Salts add randomness to key derivation. Learn how salts differ from JWT signing secrets.
CSRF and JWT Cookies
How cross-site request forgery interacts with JWT cookies, and defenses like SameSite, CSRF tokens, and careful cookie design.
E
Environment Variables
Environment variables inject secrets at runtime. Learn 12-factor patterns for JWT keys.
ES256 (ECDSA-SHA256)
ES256 uses elliptic curve keys for compact asymmetric JWT signing. Learn when ES256 beats RS256.
exp (Expiration) Claim
The exp claim sets when a JWT expires. Learn why short-lived tokens are critical for security.
H
HMAC (Hash-based Message Authentication Code)
HMAC combines a hash function with a secret key. Learn how HMAC powers HS256 JWT signatures.
HS256 (HMAC-SHA256)
HS256 uses a shared secret to sign JWTs. Learn when HS256 is the right choice and its key length requirements.
HS384 (HMAC-SHA384)
HS384 uses HMAC with SHA-384 for JWT signing. Learn when HS384 fits your security policy.
HS512 (HMAC-SHA512)
HS512 uses SHA-512 HMAC for JWT signing. Learn secret length requirements and tradeoffs.
I
J
JSON Web Key Set
A JSON Web Key Set bundles multiple public keys for JWT verification endpoints.
JSON Web Token (JWT)
Learn what a JSON Web Token is, how header, payload, and signature work, and why JWTs power modern authentication.
jti (JWT ID) Claim
The jti claim provides a unique ID for replay detection and token revocation tracking.
JWE (JSON Web Encryption)
JWE encrypts JWT claims for confidentiality. Learn when encryption beats signing alone.
JWK (JSON Web Key)
A JWK represents a cryptographic key in JSON for JWT verification and JWKS endpoints.
JWKS Endpoint
A JWKS endpoint publishes public keys for JWT verification. Essential for RS256 and ES256.
JWKS URI
What a JWKS URI is, how OIDC jwks_uri metadata works, and how verifiers should fetch and cache signing keys safely.
JWS (JSON Web Signature)
JWS is the signed JWT format with header, payload, and signature. Learn how JWS differs from JWE.
JWT Clock Skew
How clock skew affects JWT exp and nbf validation, safe leeway settings, and how to avoid weakening expiry checks.
JWT crit Header
What the JOSE crit header means, why unknown critical headers must fail verification, and how to use crit safely.
JWT cty Header
Understand the JWT cty content-type header for nested JWTs and when to set application-specific payload types.
JWT Header
The JWT header declares the signing algorithm and token type. Learn why alg validation prevents attacks.
JWT jku Header
What the jku header is, how attackers abuse remote JWK URLs, and how to pin trusted JWKS endpoints instead.
JWT Payload
The JWT payload holds claims about the subject and token metadata. Learn registered and custom claims.
JWT Secret Entropy
What entropy means for JWT HMAC secrets, how many bits you need for HS256, and why passwords fail as signing keys.
JWT Secret Key
What is a JWT secret key? Learn how HMAC signing secrets work and why key quality determines JWT security.
JWT Token Replay
What token replay means for JWTs, how attackers reuse stolen bearer tokens, and defenses like short exp, jti, and sender constraints.
JWT typ Header
What the JWT typ header means, when it is JWT vs JOSE, and how libraries treat the optional type parameter.
JWT x5c Header
What the x5c header contains, how certificate chains appear in JWTs, and how to validate them without trusting unverified chains.
JWT x5u Header
Learn what x5u means in JOSE headers, the risks of fetching certificates from token URLs, and safer certificate pinning options.
JWT zip Header
What the JOSE zip header means for compressed JWE content, when compression helps, and security caveats around compressing secrets.
K
Key ID (kid)
What a JWT key ID is, how kid maps to JWKS entries, and mistakes that cause invalid signature errors after rotation.
Key Rotation
Key rotation replaces signing keys periodically or after compromise. Plan before you need it.
Key Rotation with kid
How to rotate JWT signing keys using the kid header, dual verification windows, and JWKS publication without downtime.
kid (Key ID) Claim
The kid header identifies which signing key was used. Essential for zero-downtime JWT secret rotation.
M
N
O
P
Passphrase
What a passphrase is, how diceware-style word lists create entropy, and when to use passphrases vs random passwords or JWT secrets.
PEM Encoding
PEM encodes cryptographic keys in Base64 text. Learn how PEM relates to JWKS and RS256.
PKCS #8 Private Key Format
What PKCS #8 is, how it relates to PEM private keys for RS256, and how to store PKCS #8 material safely.
PS256 (RSA-PSS-SHA256)
PS256 uses RSA-PSS padding for JWT signatures. Learn how PS256 differs from RS256.
R
Refresh Token
Refresh tokens renew access tokens without re-login. Learn rotation and storage best practices.
RS256 (RSA-SHA256)
RS256 uses RSA public/private key pairs for JWT signing. Learn when asymmetric signing fits microservices.
RSA Cryptography
RSA is the public-key algorithm behind RS256 and PS256 JWT signing. Learn key sizes and PEM usage.
S
scope Claim
The scope claim lists granted permissions. Learn how scopes drive API authorization.
Secrets Manager
Secrets managers store and rotate JWT signing keys securely. Compare AWS, Vault, and others.
Session Cookie
Session cookies store session IDs server-side. Compare with JWT-based stateless authentication.
SHA-256
SHA-256 is the hash behind HS256 and RS256. Learn its role in JWT cryptography.
SHA-512
SHA-512 produces 512-bit hashes used in HS512. Learn when larger digests matter.
Signing Key Compromise
What to do when a JWT signing key leaks: emergency rotation, session invalidation, and preventing repeat exposure.
SPKI Public Key Format
What SPKI public key encoding is, how PEM PUBLIC KEY blocks relate to JWT verification, and how SPKI differs from PKCS #8.
Stateless Authentication
Stateless authentication validates JWTs without server-side session storage. Learn tradeoffs vs sessions.
sub (Subject) Claim
The sub claim identifies the principal the JWT is about. Learn subject design for multi-tenant apps.
T
U
Z
Frequently Asked Questions
What is a JWT glossary term?
Each entry defines one JWT or cryptography concept in plain language — algorithm names, standard claims, token formats, and security primitives used when building authentication systems.
How do I use the JWTSecrets glossary?
Search alphabetically or start from core terms like JWT, HS256, and jwt-secret. Each page links to related tools, comparisons, and blog guides for deeper context.
Are glossary definitions enough for production security?
Definitions explain concepts; production systems still need proper secret storage, algorithm allowlists, short token lifetimes, and signature verification in code — use our tools and guides alongside these definitions.
How is this glossary different from RFC 7519?
RFC 7519 is the formal specification. Our glossary translates those standards into developer-friendly explanations with practical security guidance and links to working browser tools.