> For the complete documentation index, see [llms.txt](https://x7331.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://x7331.gitbook.io/notes/apisec/api-authentication/json-web-tokens.md).

# JSON Web Tokens

<table><thead><tr><th width="111" align="right">Feature</th><th width="175" align="right">Description</th><th>Details</th></tr></thead><tbody><tr><td align="right">Format</td><td align="right">How is it encoded</td><td><ol><li><strong>By value</strong> (contains all the details within it, can be validated by the receiver without calling the AS, can be encrypted/signed, e.g. JWTs, SAML, CWTs, etc.)</li><li><strong>By reference</strong> (random string that acts as a reference to a db entry; only the AS can read it)</li></ol></td></tr><tr><td align="right">Purpose</td><td align="right">Who is it for</td><td><ol><li><strong>Access token</strong> -> Resource Server</li><li><strong>Refresh token</strong> -> Authorization Server</li><li><strong>ID Token</strong> (OpenID Connect) -> Client</li></ol></td></tr><tr><td align="right">Type</td><td align="right">How can it be used</td><td><ol><li><strong>Bearer</strong> (coin analogy -> if you find one, you don't need to prove that it is yours, you can use it as is)</li><li><strong>Proof of Possession (PoP)/Holder of Key (HoK)</strong> (credit card analogy -> you need proof of ownership to use them. They are <em>sender-constrained tokens</em>, i.e., bound to a single user)</li></ol></td></tr></tbody></table>

<figure><img src="https://3960676229-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmjLkek16kB60c2WFd5lf%2Fuploads%2Fz5PsPueS1pPiKCKn7Oi6%2Faccess_token_examples.png?alt=media&amp;token=ca9818f0-a8e4-4a14-a03f-2708615eb24f" alt=""><figcaption></figcaption></figure>

## JSON Web Tokens

* JWT is a **format**
* Can be used for many purposes
  * ID Tokens are always JWTs
  * Access tokens **can be** JWTs
  * Refresh tokens **are (almost) never** JWTs
* Most often are signed (**JWS**)
* Can be encrypted (**JWE**)

<figure><img src="https://3960676229-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmjLkek16kB60c2WFd5lf%2Fuploads%2FnwbIrBqlN4czRfSIsKyg%2Fjwt_token_format.png?alt=media&amp;token=7ce0c910-89d9-45ee-ac10-1c158ad67c3a" alt=""><figcaption></figcaption></figure>
