RFC 7519: JSON Web Token (JWT)
In plain English — editorial summary, not part of the RFC
JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is used as the payload of a JSON Web Signature (JWS) structure or as the plaintext of a JSON Web Encryption (JWE) structure, enabling the claims to be digitally signed or integrity protected with a Message Authentication Code (MAC) and/or encrypted.
Document record
- Document ID
- RFC7519
- Published
- May 2015
- Authors
- M. Jones; J. Bradley; N. Sakimura
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 30
- Also known as
- —
Topics
Referenced by
2 later RFCs formally update or obsolete part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7520Examples of Protecting Content Using JSON Object Signing and Encryption (JOSE)Current
May 2015
- RFC 7517JSON Web Key (JWK)Current
May 2015
- RFC 7516JSON Web Encryption (JWE)Current
May 2015
- RFC 7515JSON Web Signature (JWS)Current
May 2015
- RFC 9101The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR)Current
August 2021
- RFC 7165Use Cases and Requirements for JSON Object Signing and Encryption (JOSE)Current
April 2014
- RFC 7638JSON Web Key (JWK) ThumbprintCurrent
September 2015
- RFC 8414OAuth 2.0 Authorization Server MetadataCurrent
June 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?