Connexion
  • Développement

    Documentation

    • Documentation Auth0 for AI
    • API
    • Kits SDK
    • Catalogue d’événements
    • Journal des modifications
    • Échantillons de code↗
    • Guides↗
    • Consulter la documentation Auth0→

    Guides de démarrage rapide

    • React
    • Next.js
    • Angular
    • Vue.js
    • React Native
    • iOS / Swift
    • Développez dans plus de 30 langages et frameworks
    • Voir tous les guides de démarrage rapide→

    Outils de développement

    • Décodeur JWT↗
    • Démo WebAuthn↗
    • OIDC Playground↗
    • Outil SAML↗
    • Passkeys Playground↗
    • Auth0 Deploy CLI↗
    • État d’Auth0↗

    Connecter

    • Communauté↗
    • Base de connaissance↗
    • Centre de support↗
    • Developer Center↗
    • Marketplace↗
    • Événements↗
      • Camp AI pour les développeurs↗
      • Participer à l’événement Vercel Ship↗
      • Auth0 à la conférence MCP Dev Summit↗
  • Produits

    Identité de l’IA

    • Auth0 for AI Agents
      • Authentification
      • Token Vault
      • Auth for MCP

    FEATURED CONTENT

    LIVRE BLANC

    Qu’est-ce qu’Auth0 for AI Agents ?

    Identité des clients

    • Universal Login
    • Passwordless
    • Gestion des utilisateurs
    • Authentification
    • Mots de passe compromis
    • Embedded Login
  • Solutions

    Cas d’usage

    • Enterprise
    • B2B
    • B2C
    • Startups
    • Organisations à but non lucratif

    Profils cibles

    • Services financiers
    • Santé
    • Commerce de détail
    • Partenaires
  • Bibliothèque

    Explorer par thème

    • IA
    • Développeurs
    • Identité et sécurité
    • Activités
    • Ingénierie
    • Annonces
    • Consulter le blog→

    Explorer par type

    • eBooks
    • Vidéos
    • Podcasts
    • Webinars
    • Prochains webinars
    • Livres blancs
    • Parcourir les ressources→
  • Tarifs
  • Langue

Inscription
Connexion
Apprenons à nous connaître
  • Développement

    Documentation

    • Documentation Auth0 for AI
    • API
    • Kits SDK
    • Catalogue d’événements
    • Journal des modifications
    • Échantillons de code↗
    • Guides↗
    Consulter la documentation Auth0→

    Guides de démarrage rapide

    • React
    • Next.js
    • Angular
    • Vue.js
    • React Native
    • iOS / Swift
    • Développez dans plus de 30 langages et frameworks
    Voir tous les guides de démarrage rapide→

    Outils de développement

    • Décodeur JWT↗
    • Démo WebAuthn↗
    • OIDC Playground↗
    • Outil SAML↗
    • Passkeys Playground↗
    • Auth0 Deploy CLI↗
    • État d’Auth0↗

    Connecter

    • Communauté↗
    • Base de connaissance↗
    • Centre de support↗
    • Developer Center↗
    • Marketplace↗
    • Événements↗
      • Camp AI pour les développeurs↗
      • Participer à l’événement Vercel Ship↗
      • Auth0 à la conférence MCP Dev Summit↗
  • Produits

    Identité de l’IA

    • Auth0 for AI Agents
      • Authentification
      • Token Vault
      • Auth for MCP

    FEATURED CONTENT

    LIVRE BLANC

    Qu’est-ce qu’Auth0 for AI Agents ?

    Identité des clients

    • Universal Login
    • Passwordless
    • Gestion des utilisateurs
    • Authentification
    • Mots de passe compromis
    • Embedded Login

    Connectivité de l’entreprise

    • Authentification unique (SSO)
    • Authentification multifacteur (MFA)
    • Sécurité des connexions
    • Organizations

    Autorisation

    • Autorisation granulaire
    • Gestion des accès
    • Machine-to-machine

    Plateforme et extensibilité

    • Déploiements cloud
    • Actions
    • Forms
    • Highly Regulated Identity
    • Extensibilité
  • Solutions

    Cas d’usage

    • Enterprise
    • B2B
    • B2C
    • Startups

      Tarifs spéciaux

    • Organisations à but non lucratif

      Tarifs spéciaux

    Profils cibles

    • Services financiers
    • Santé
    • Commerce de détail
    • Partenaires

    Populaire

    • Customer Identity Trends Report
    • Déploiement des agents d’IA
    • Playbooks architecture
      • Identité
      • Connecter

    FEATURED CONTENT

    LIVRE BLANC

    Du prototype à la production

  • Bibliothèque

    Explorer par thème

    • IA
    • Développeurs
    • Identité et sécurité
    • Activités
    • Ingénierie
    • Annonces
    Consulter le blog→

    Explorer par type

    • eBooks
    • Vidéos
    • Podcasts
    • Webinars
    • Prochains webinars
    • Livres blancs
    Parcourir les ressources→

    Éducation

    • Auth0 Learning↗
    • Introduction à l’IAM (CIAM)
    • Newsletter Zero Index↗
    • Témoignages clients

    FEATURED CONTENT

    WEBINAR

    Auth0 Launchpad

  • Tarifs
Inscription
Apprenons à nous connaître

PREMIERS PAS AVEC AUTH0

  • CIAM Auth0
  • Introduction à l’IAM
  • Auth0 Platform
  • Fonctionnalités d’Auth0
  • Tarifs
  • Essayez Okta gratuitement

DOCUMENTATION

  • Documentation
  • Guides de démarrage rapide
  • API
  • Bibliothèques de kits SDK
  • Journal des modifications
  • Déployer sur Azure
  • Déployer sur AWS

CONTACT ET AIDE

  • Centre de support
  • Demander de l’aide à la communauté
  • Contacter l’équipe commerciale
  • Contacter un ingénieur
  • État d’Auth0 ↗

ENTREPRISE ET CONFIANCE

  • Conformité, confidentialité et sécurité ↗
  • À propos d’Auth0 ↗
  • Carrières ↗
  • Partenaires

Contacter un expert en vente ou en ingénierie

Nous contacter
©2026 Okta, Inc. All Rights Reserved.
  • État
  • Juridique
  • Confidentialité
  • Conditions
  • Vos choix en matière de confidentialité
Français
RESOURCES

JWT Handbook

SHARE ON

JWT Handbook

Pour obtenir l’eBook, remplissez le formulaire

À propos de cet eBook

Ever wondered how JWT came to be and what problems it was designed to tackle?

Are you curious about the plethora of algorithms available for signing and encrypting JWTs?

Or are you interested in getting up-to-speed with JWTs as soon as possible? Then this handbook is for you.


TABLE OF CONTENTS

Contents

  1. Special Thanks 4
  2. Introduction 5
    1. What is a JSON WebToken? 5
    2. What problem does it solve? 6
    3. A little bit of history 6
  3. Practical Applications 8
    1. Client-side/Stateless Sessions 8
      1. Security Considerations 9
        1. Signature Stripping 9
        2. Cross-Site Request Forgery (CSRF) 10
        3. Cross-Site Scripting (XSS) 11
      2. Are Client-Side Sessions Useful? 13
      3. Example 13
    2. FederatedIdentity 16
      1. Access and Refresh Tokens 18
      2. JWTs and OAuth2 19
      3. JWTs and OpenID Connect 20
        1. OpenID Connect Flows and JWTs 20
      4. Example 20
        1. Setting up Auth0 Lock for Node.js Applications 21
  4. JSON Web Tokens in Detail 23
    1. The Header 24
    2. The Payload 25
      1. Registered Claims 25
      2. Public and Private Claims 26
    3. Unsecured JWTs 27
    4. Creating an Unsecured JWT 27
      1. Sample Code 28
    5. Parsing an Unsecured JWT 28
      1. Sample Code 29
  5. JSON Web Signatures 30
    1. Structure of a Signed JWT 30
      1. Algorithm Overview for Compact Serialization 32
      2. Practical Aspects of Signing Algorithms 33
      3. JWS Header Claims 36
      4. JWS JSON Serialization 36
        1. Flattened JWS JSON Serialization 38
    2. Signing and Validating Tokens 38
      1. HS256: HMAC 1. SHA-256 39
      2. RS256: RSASSA 1. SHA256 39
      3. ES256: ECDSA using P-256 and SHA-256 40
  6. JSON Web Encryption (JWE) 41
    1. Structure of an Encrypted JWT 44
      1. Key Encryption Algorithms 45
        1. Key Management Modes 46
        2. Content Encryption Key (CEK) and JWE Encryption Key 47
      2. Content Encryption Algorithms 48
      3. The Header 48
      4. Algorithm Overview for Compact Serialization 49
      5. JWE JSON Serialization 50
        1. Flattened JWE JSON Serialization 52
    2. Encrypting and Decrypting Tokens 52
      1. Introduction: Managing Keys with node-jose 52
      2. AES-128 Key Wrap (Key) 1. AES-128 GCM (Content) 54
      3. RSAES-OAEP (Key) 1. AES-128 CBC 1. SHA-256 (Content) 54
      4. ECDH-ESP-256 (Key)1. AES-128 GCM (Content) 55
      5. Nested JWT: ECDSA using P-256 and SHA-256 (Signature) 1. RSAES-OAEP (Encrypted Key) 1. AES-128 CBC 1. SHA-256 (Encrypted Content) 55
      6. Decryption 56
  7. JSON Web Keys (JWK) 58
    1. Structure of a JSON Web Key 59
      1. JSON Web Key Set 60
  8. JSON Web Algorithms 61
    1. General Algorithms 61
      1. Base64 61
        1. Base64-URL 63
        2. Sample Code 63
      2. SHA 64
    2. Signing Algorithms 69
      1. HMAC 69
        1. HMAC 1. SHA256 (HS256) 71
      2. RSA 73
        1. Choosing e, d and n 75
        2. Basic Signing 76
        3. RS256: RSASSA PKCS1 v1.5 using SHA-256 76
          1. Algorithm 76
            1. EMSA-PKCS1-v1_5 primitive 78
            2. OS2IP primitive 79
            3. RSASP1 primitive 79
            4. RSAVP1 primitive 80
            5. I2OSP primitive 80
          2. Samplecode 81
        4. PS256: RSASSA-PSS using SHA-256 and MGF1 with SHA-256 86
          1. Algorithm 86
            1. MGF1: the mask generation function 87
            2. EMSA-PSS-ENCODE primitive 88
            3. EMSA-PSS-VERIFY primitive 89
          2. Sample code 91
      3. Elliptic Curve 94
        1. Elliptic-Curve Arithmetic 96
          1. Point Addition 96
          2. Point Doubling 97
          3. Scalar Multiplication 97
        2. Elliptic-Curve Digital Signature Algorithm (ECDSA) 98
          1. Elliptic-Curve Domain Parameters 100
          2. Public and Private Keys 101
            1. The Discrete Logarithm Problem 101
          3. ES256: ECDSA using P-256 and SHA-256 101
    3. Future Updates 104

Hosted By

Sebastián Peyrott

Sebastián Peyrott

Envie de passer à Auth0 ?

Auth0 peut être intégré à toutes les applications, dans tous les langages et tous les frameworks, en quelques lignes de code.

Créer un compte gratuitement→

Démarrer avec Auth0

Adoptez une identité client de premier ordre, avec une sécurité intégrée️.

S’inscrire
Contactez le service commercial