2 ms·
I'm surprised this has picked up a fancy name and full libraries for so many languages. Not to mention the use of "JWT" as the acronym, which is already famous
by hatethis 12y ago
I'm surprised this has picked up a fancy name and full libraries for so many languages. Not to mention the use of "JWT" as the acronym, which is already famous for "Java Web Toolkit". It's just an HMAC token for validating the integrity of the data - it proves the data has not been modified, that's it. People have been using this for years, perhaps most popularly used by Facebook to sign API requests and responses.
A side note for anyone considering the use of timestamps within the payload for expiry: note that if you are going to have multiple machines verifying expiries, they will need to be using NTP to ensure that all machines have the same current timestamp at all times.
- gobengo 12y ago'just an hmac token', but attached to the payload in a well-structured way. Very required for the proliferation of libraries across all languages. There is also JSON Web Encryption, built on top of JWT, which provides encryption in addition to signatures. https://tools.ietf.org/html/draft-ietf-jose-json-web-encryption-31 https://tools.ietf.org/html/draft-ietf-jose-json-web-encrypt...