JSON Web Token (JWT)
A compact, URL-safe token format defined in RFC 7519 that carries claims as JSON, usually signed so the recipient can detect tampering, and widely used for ID and access tokens.
A JSON Web Token (JWT), defined in RFC 7519, is a compact way to pass a set of claims (statements such as who the user is, who issued the token, and when it expires) between parties. In its common signed form it has three base64url-encoded parts separated by dots: a header naming the algorithm, a payload of claims, and a signature. The signature follows JSON Web Signature (RFC 7515); JSON Web Encryption (RFC 7516) provides an encrypted form.
The distinction candidates commonly miss is that a signed JWT is protected for integrity, not confidentiality. Anyone who holds the token can decode and read its payload, so secrets do not belong in it unless it is encrypted. The recipient has to check the signature, issuer, audience and expiry before trusting a claim. Many JWTs are also bearer tokens: whoever presents one is treated as its rightful holder, so theft matters as much as forgery. OpenID Connect requires its ID token to be a JWT, and many systems use the format for OAuth access tokens, although OAuth 2.0 does not require it.
Exam relevance: a scenario is likely to ask what a signed token protects. Candidates are expected to answer integrity and origin, not secrecy, and to recognise that a stolen valid token works for whoever presents it.