Security · Fill in the blank

Anyone holding a signed JWT can read its claims: the payload is only blank-encoded, not encrypted. The signature proves the claims were not blank.

easy

Answer

Anyone holding a signed JWT can read its claims: the payload is only base64url-encoded, not encrypted. The signature proves the claims were not changed.

Also accepted: base64 for base64url; modified, tampered with, altered for changed.

Why

Do not put secrets or sensitive personal data in a JWT; it ends up in browser storage, logs and proxies. If the claims must be hidden, encrypt them (JWE) or use an opaque token that points to server-side data.

Review this in your daily deck All cards in Security