---
title: "JWT Reference Cheatsheet | FindUtils"
description: "Signed JWT claims, algorithms, verification checks, and the distinction between JWS and JWE."
url: https://findutils.com/cheatsheets/jwt-reference/
---

# JWT Reference Cheatsheet

Signed JWT claims, algorithms, verification checks, and the distinction between JWS and JWE. 37 commands in 7 sections, filed under [Web Development](https://findutils.com/cheatsheets/web/).

## Shape

- `header.payload.signature`: Signed compact JWS form; encrypted JWTs use JWE and a different structure
- `typ`: Usually JWT
- `alg`: Signature algorithm in the header
- `HS256`: HMAC SHA-256 with a shared secret
- `RS256`: RSASSA-PKCS1-v1_5 SHA-256
- `ES256`: ECDSA P-256 SHA-256
- `none`: Unsigned; reject this on verify

## Registered claims

- `iss`: Issuer
- `sub`: Subject
- `aud`: Audience
- `exp`: Expiration time (unix seconds)
- `nbf`: Not before (unix seconds)
- `iat`: Issued at (unix seconds)
- `jti`: JWT ID

## Header flags

- `kid`: Key id for key lookup
- `jku`: JWK set URL; treat as untrusted input
- `x5u`: X.509 cert URL; treat as untrusted input
- `x5c`: X.509 cert chain in the header
- `cty`: Content type for nested JWTs

## Verify rules

- `Check alg allow-list`: Do not trust the header alg blindly
- `Reject alg=none`: Unsigned tokens must fail verify
- `Check exp`: Reject expired tokens
- `Check nbf`: Reject tokens used too early
- `Check aud and iss`: Must match the expected values
- `Decode is not verify`: Reading claims does not prove the signature

## Inspect locally

- `FindUtils JWT Decoder`: Decode header and payload in the browser
- `Do not paste production secrets`: Treat tokens as credentials
- `Look at alg first`: HS256 and RS256 use different key types; none has no signature key
- `Check exp as unix time`: Compare to the current unix timestamp
- `PEM Decoder for x5c`: Inspect a pasted cert, not a live host

## Common mistakes

- `HS256 with a public key`: Attackers can forge if verify accepts HMAC
- `alg confusion`: Lock the expected algorithm in code
- `Long-lived exp`: Stolen tokens stay valid too long
- `Put secrets in payload`: A signed JWS payload is encoded, not encrypted; keep secrets out
- `Skip aud`: A token for another app may still verify

## Sources

- `https://www.rfc-editor.org/rfc/rfc7519.html`: RFC 7519: JWT claims, signed JWS tokens, encrypted JWE tokens, and validation.
- `https://www.rfc-editor.org/rfc/rfc7518.html`: RFC 7518: HMAC, RSA signatures, algorithm identifiers, and unsecured JWS.

## Related

- Cheatsheet: [React Hooks](https://findutils.com/cheatsheets/react-hooks/)
- Cheatsheet: [CSS Flexbox](https://findutils.com/cheatsheets/css-flexbox/)
- Cheatsheet: [CSS Grid](https://findutils.com/cheatsheets/css-grid/)
- Guide: [JWT Generator: Create Signed JSON Web Tokens Online](https://findutils.com/guides/jwt-generator-guide/)
- Guide: [JWT Decoder: Decode & Inspect JSON Web Tokens Online](https://findutils.com/guides/jwt-decoder-guide/)
- Tool: [JWT Decoder](https://findutils.com/developers/jwt-decoder/)
